Wall Street hackers launch AI vishing campaign targeting Citadel, Two Sigma, Point72
Investment firms have overtaken banks as finance’s most targeted subindustry.

Image by Cybernews
- Hackers used AI-powered voice phishing to target employees at hedge fund giants Citadel, Two Sigma, and Point72.
- The attacks rely on voice phishing rather than malware, exploiting employee trust to gain access.
- Investment firms have overtaken banks as cybercriminals' top financial target, with attacks nearly doubling since 2023.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Several of the world’s largest hedge funds – including Citadel, Millennium Management, Two Sigma Investments, and Point72 Asset Management – are targeted this week as part of a sophisticated AI-fueled voice phishing campaign, Bloomberg reported on Wednesday.
Several private equity firms were also said to have been caught up in the attacks, although the names of the companies involved were not revealed for confidentiality reasons, the news outlet said.
AI-powered vishing hits Wall Street
Point72 Asset Management alerted investors to the attack on Wednesday, according to two sources familiar with the matter.
The global asset management firm said that no client data had been accessed, while Two Sigma – which said it was able to block the attackers – is still reviewing the incident.
“Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,”Two Sigma said in a statement.
“We continue to monitor the situation closely,” the spokesperson said.
Citadel and Millennium Management have not publicaly commented on the attacks.
The total Assets Under Management (AUM) handled by the top Wall Street giants are as follows:
- Millennium Management - $77.5 billion
- Two Sigma - $75 billion
- Citadel - $67.6 billion
- Point72 - $50.7 billion
How hackers use AI voice phishing
According to Bloomberg, the unknown threat actor began targeting employees at the firms over the past few days using AI-generated voices – a social engineering tactic known as vishing, short for voice phishing.
The attacks – carried out via phone calls or voice messages – are designed to trick an employee into revealing login information or other sensitive credentials, thereby allowing the threat actor to gain unauthorized access to the company’s internal systems.
Typically, attackers will use AI to clone the voices of higher-ups or simply impersonate IT support, convincing employees to reset passwords, share one-time authentication codes, or approve fraudulent access requests.
Financial firms remain prime targets
Vishing attacks have surged among extortion groups in recent years, with notable gangs such as the Scattered Lapsus$ Hunters (SHL) trio – perfecting IT help desk attacks against third-party vendors to carry out month-long breaches of Marks & Spencer (M&S) and Jaguar Land Rover (JLR) in 2025, among many others.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Investment firms have also become a favored target of cybercriminals in 2025, displacing traditional banking institutions as the most-targeted subindustry in the finance sector, according to Black Kite's recently released 2026 Financial Services Cybersecurity Report.
Black Kite says ransomware attacks on the finance sector overall rose by 30% in 2025 and were already up another 76% in the first quarter of 2026, with investment firms accounting for roughly 40% of all finance-sector disclosures.
Check if your data has been leaked