Wall Street cyberattacks put Point72 and peers on alert

Wall Street cyberattacks targeted Point72, Two Sigma and other investment firms, intensifying scrutiny of vishing threats across finance.

Atlas Newsdesk ·

Wall Street cyberattacks put Point72 and peers on alert

Wall Street cyberattacks have hit leading investment firms, with Point72 telling investors it was attacked and peers facing attempted intrusions.

People familiar with the matter said the recent activity focused on information systems at hedge funds and private equity firms. The targets included Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel and several buyout firms, according to those people.

Point72 reviews client exposure

Point72 informed investors on Wednesday that it had been attacked, one person familiar with the notice said. Early signs indicated client information had not been taken, though the firm was still examining the incident, the person said.

The distinction matters because a blocked intrusion and a confirmed theft trigger very different legal, client and regulatory responses. Spokespeople for Point72, Millennium and Citadel declined to comment, according to the source material.

Two Sigma cites no impact

Two Sigma Investments, which oversees $75 billion in assets, said it stopped an attempt to reach sensitive information. A spokesperson said, "Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems."

The spokesperson added, "We continue to monitor the situation closely." The statement places Two Sigma in the narrower category of firms that publicly described the event as attempted access rather than a confirmed systems compromise.

Vishing tests phone controls

The attacks used voice phishing, known as vishing, people familiar with the matter said. In that method, criminals impersonate a trusted voice through calls or messages to push employees into sharing credentials, approving access or bypassing normal checks.

Vinod Paul, president of Align Managed Services, said artificial intelligence has changed the economics of cybercrime against hedge funds and other financial firms. "Before they could attack 50 entities in a targeted attack, now they can do 1,000," Paul said.

Paul said attackers can also exploit real conversations to improve impersonation. "Hackers can also listen into a phone call and mimic the voice, tone and phrasings of the speakers to create fake calls," he said.

A cybersecurity unit at Google said in June that law firms and other professional-services companies had faced similar campaigns this year. Those incidents included vishing and, in some cases, people entering offices while posing as technology staff, according to the unit's blog post.

Finra portal gains relevance

The Financial Industry Regulatory Authority has contacted member firms about recent attempted breaches, according to a person familiar with the matter. Finra, which oversees broker-dealers and securities professionals, declined to comment.

Finra created the Financial Intelligence Fusion Center in March as a secure channel for sharing fraud intelligence with member firms. The portal was designed to help coordinate responses as cyber and fraud threats against financial-services companies became more sophisticated.

The industry risk is not confined to any single hedge fund. If attackers can use cheap voice-cloning tools to multiply attempts, banks, brokers, funds and private equity firms may need stronger call-back procedures, access reviews and employee training around urgent phone requests.

The macro channel is operational rather than traditional credit stress. If attempted breaches remain contained, the effect on global markets is likely limited to higher security spending and tighter internal controls; if a major breach disrupts trading or settlement workflows, counterparties may slow approvals and regulators may press firms to share threat intelligence faster.

For Point72, the central question is whether its review confirms the early view that client data was not stolen. For the wider sector, the test is whether vishing remains a manageable employee-training problem or becomes a scaled access threat that forces a redesign of how financial firms verify identity.

More stories