Hackers launched a coordinated phishing campaign against major Wall Street money managers and hedge funds, including Two Sigma, Citadel, Point72 and Millennium Management, according to reporting on August 5. The attacks also targeted multiple private equity firms and used voice phishing techniques to attempt credential theft from employees.

Voice phishing, also called vishing, relies on phone calls rather than emails to deceive targets into revealing passwords or authentication details. Email filters do not catch these calls, and attackers exploit human trust in spoken conversations. Affected firms and law enforcement are investigating whether the attackers successfully breached any systems or obtained sensitive data.

Gain total value locked, last 90 days
Gain total value locked, last 90 days · MSB Intel data desk

Two Sigma, founded in 2001, manages roughly $65 billion in assets and is among the largest quantitative hedge funds in the world. Citadel, a $62 billion multi-strategy fund, and Point72, which oversees approximately $23 billion, are also major institutional players that handle significant trading volumes and proprietary data. Attackers targeted firms across multiple firms rather than pursue a single entity.

MSB Intel

Private equity firms and hedge funds have become frequent targets for cybercriminals seeking access to deal information, trading strategies or financial data. In 2024, major financial institutions reported a 40 percent increase in phishing attempts compared to the prior year, according to industry security surveys. Voice phishing attacks specifically rose as bad actors refined their ability to impersonate colleagues or IT staff through social engineering.

The affected firms have begun reinforcing multi-factor authentication requirements and conducting security awareness training across their staff. Citadel and Two Sigma did not immediately respond to requests for comment on the scope of the incident or any measures taken beyond internal investigation.

The Securities and Exchange Commission has proposed new rules requiring registered investment advisers to report cybersecurity incidents to the agency within 72 hours. A successful breach at a major hedge fund could trigger significant regulatory consequences and potential client losses if proprietary trading models or fund performance data were exposed.

Federal authorities including the FBI are assisting in the investigation. The number of firms ultimately caught in the phishing net and whether any attackers succeeded in penetrating defended networks remain unclear pending the completion of forensic reviews.