Vishing Campaign Targets Major Hedge Funds

Bloomberg reported on August 5 that major hedge funds and other Wall Street firms were targeted in a recent wave of cyberattacks. Gizmodo, citing Bloomberg, reported that Citadel, Two Sigma, and Point72 were among firms targeted by AI-enabled voice-phishing, or vishing, attempts. Two Sigma told Bloomberg it detected the attack before its internal systems were compromised.
Bloomberg reported on August 5 that major hedge funds and other Wall Street firms were targeted in a recent wave of attempted cyberattacks. Gizmodo, citing Bloomberg's reporting, identified Citadel, Two Sigma, and Point72 among the hedge funds reportedly targeted, alongside several private-equity firms.
The attacks reportedly used voice phishing, commonly called vishing, in which attackers use AI-generated or AI-simulated voices to impersonate people and bypass security controls. According to Gizmodo's account of the Bloomberg report, Two Sigma detected the attempt before its internal systems were compromised. Citadel and Point72 did not immediately respond to Gizmodo's requests for comment.
Bloomberg also reported that one unnamed hedge fund informed investors it had been attacked. According to a person familiar with the matter cited by Bloomberg, the firm's initial indication was that no client information had been stolen, while its review remained ongoing.
What vishing changes
Vishing is not new, but accessible voice-cloning and generative AI systems can make impersonation attempts more convincing and scalable. In financial services, a convincing call can target help desks, executives, trading operations, fund administrators, or third-party vendors with requests to reset credentials, alter payment instructions, or disclose sensitive information.
Public reporting has not established the attackers' identities, technical methods, or whether any systems beyond the reported Two Sigma attempt were compromised. Those gaps matter because successful voice impersonation can function as an initial-access technique rather than a standalone incident.
Companies facing comparable threats commonly reduce exposure by requiring out-of-band verification for high-risk requests, limiting help-desk authority to reset privileged accounts, and monitoring for unusual identity-verification or payment-change workflows. For security teams, the reported campaign is a reminder that voice should not be treated as a reliable authentication factor when synthetic speech can imitate trusted personnel.
Key Points
- 1Bloomberg reported a recent attack wave against major hedge funds, demonstrating that financial firms remain high-value targets for social engineering.
- 2Two Sigma reportedly stopped the attempt before internal compromise, underscoring the value of detection and verification controls during identity-based attacks.
- 3AI voice synthesis can scale impersonation attempts, making independent verification more important than voice recognition for sensitive operational requests.
Scoring Rationale
The reported campaign concerns AI-enabled social engineering against prominent financial institutions, a material security issue for organizations handling sensitive workflows. Technical details and confirmed compromise information remain limited, which constrains its immediate operational significance.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
