Wall Street Hedge Funds Face Wave of Voice Phishing Attacks: Report
Point72, Citadel and Millennium Management were among major Wall Street hedge funds targeted by callers impersonating trusted colleagues and IT support staff.
Topics
Several of Wall Street’s biggest hedge funds, including Point72 Asset Management, Citadel and Millennium Management, have been targeted in a series of cyberattacks involving fraudulent phone calls, the Financial Times reported, citing people familiar with the incidents.
The attackers used voice phishing, or “vishing,” to impersonate trusted colleagues and persuade employees to disclose credentials or provide access to company systems, the report said.
At one hedge fund, callers posed as members of the company’s IT help desk and sought login details for employees’ authenticator applications, which provide an additional layer of security beyond passwords.
Point72 contacted law enforcement and hired cybersecurity specialists as it investigated whether its systems had been breached, the FT said. The firm told investors on Wednesday, 5 August, that it did not believe client information had been stolen.
Citadel did not appear to have been breached, according to the report. It remained unclear who was behind the attacks or whether the incidents were coordinated by a single group.
Reuters separately reported that Point72, Citadel and Two Sigma Investments were among firms targeted. The report described attempts to trick employees over the phone into granting system access or disclosing sensitive information.
The attacks resemble a broader campaign documented by Google’s Mandiant cybersecurity unit.
Between January and May, a financially motivated group tracked as UNC3753 targeted dozens of US legal, professional-services and financial companies by impersonating IT support staff and persuading employees to install remote-access software. There is no public evidence so far linking that group to the hedge fund attacks.
Google said voice phishing accounted for 11% of the intrusions it investigated during 2025, making it the second-most common initial route into corporate systems.
The available reports do not establish that artificial intelligence was used in the latest attacks, despite wider concern that voice-cloning tools can make impersonation schemes more convincing.

