Skip to content

Cybersecurity Insights

Cyberattacks Against Major Hedge Funds

Posted in AI Risk Assessment, News, Social Engineering Training

Hedge Funds Targeted in Coordinated Cyberattacks

When some of the world’s largest hedge funds become targets of cybercriminals, people should start to pay attention. Let me emphatically say it another way, cyberattacks against major hedge funds should be a wake-up call to all businesses. Cybercriminals are not just targeting anyone, they are specifically targeting companies with large amounts of data and money.

Recently, several well-known Wall Street firms such as Point72, Citadel, Two Sigma, and Millennium Management were reportedly targeted in a wave of attacks. News reports say the attackers mainly used advanced voice phishing, or vishing, by pretending to be trusted people to trick employees into sharing credentials or giving access to internal IT systems. While some firms caught and stopped these attempts, the campaign shows a growing trend: attackers are focusing more on people than on software weaknesses.

This incident serves as an important reminder for business leaders.

Your firewall may be secure.

Your servers may be fully patched.

But your employees could still be the next target with just one phone call.

 

What Happened: Cyberattacks Against Major Hedge Funds?

The news reports I saw said that several major hedge funds faced a coordinated attack using voice-based social engineering. Instead of taking advantage of software flaws, attackers called employees and pretended to be trusted people like help desk staff or internal support.

The objective was simple.

Convince an employee to disclose credentials, approve a login request, or provide information that would allow attackers to access sensitive systems.

As of now, there is no public sign that the firms suffered a breach of security systems. Point72 has reportedly started an investigation and brought in law enforcement and cybersecurity experts as a precaution.

 

Why Hedge Funds?

Large financial institutions are attractive targets because they manage enormous amounts of sensitive information and money.

Cybercriminals and nation-state attackers see things like investment strategies, trading algorithms, confidential financial data, merger and acquisition details, investor records, and proprietary research as valuable targets.

But the techniques used against these firms are not limited to Wall Street.

The same tactics are being used against manufacturers, healthcare providers, law firms, construction companies, technology firms, and government contractors every day.

The only difference is the target’s size.

 

The Rise of Voice Phishing Today

For years, businesses focused on suspicious emails.

Today, many attackers are picking up the phone and simply asking standard employees for access into IT systems.

Voice phishing, also called “vishing,” mixes traditional social engineering with convincing phone calls that create a sense of urgency and trust.

An attacker may claim to be:

  • Your internal IT department
  • Microsoft support
  • Your cybersecurity provider
  • A software vendor
  • A company executive
  • A customer requesting assistance

In many cases, the employee believes they are helping solve a legitimate technical issue.

Instead, they help an attacker gain access to the network.

Artificial intelligence has made these attacks even more convincing. Attackers can now use voice cloning, personalized scripts, and quickly gather public information about potential targets.

 

Why This Matters to Every Business

One of the biggest misconceptions in cybersecurity is that attackers only target Fortune 500 companies. Most cybercriminals just look for the easiest way into a business.

Imagine walking through a neighborhood looking for an unlocked front door.

You probably wouldn’t care whether the house cost $300,000 or $30 million.

If the door is unlocked, you’ve found an opportunity.

Cybercriminals think much the same way.

While hedge funds offer big rewards, smaller businesses often have fewer security controls and less employee training.

This makes them attractive targets, too.

 

Protecting The Human Firewall

Businesses spend millions of dollars every year on cybersecurity technology.

Firewalls, endpoint detection, email security, cloud security, and identity management.

All these tools are valuable.

Still, many successful attacks start with just a simple phone call.

Technology can block malware.

But it cannot always stop an employee from trusting the wrong person.

That is why employee awareness has become one of the most important cybersecurity investments a business can make.

A well-trained employee who takes a moment to check an unusual request can prevent an incident that no software could stop.

 

How Businesses Can Reduce Their Risk

From our perspective, protecting social engineering requires more than annual security awareness training.

Employees need to know how attackers create urgency, build trust, and trick people into ignoring security steps.

Businesses should implement strong multi-factor authentication, verify identity before resetting passwords, restrict privileged account access, monitor authentication events, and regularly conduct phishing and social engineering exercises.

It’s just as important to build a culture where employees feel comfortable taking their time and asking questions.

No employee should feel pressured to approve an unusual request just because someone sounds like they are in charge.

 

Don’t Forget Your Help Desk

Many recent social engineering campaigns have specifically targeted IT support personnel.

Help desk teams routinely reset passwords, unlock accounts, enroll new devices, and assist users with experiencing standard IT problems.

These tasks also make them appealing targets.

Strong identity verification procedures should be in place before any account changes are made.

Simple verification steps can stop an attacker from turning a routine support call into a serious security problem.

 

Related Services

Social engineering keeps changing, but businesses can lower their risk with security checks and employee training. Tanner Security helps companies improve both their technical and human defenses with services such as:

Together, these services help businesses find weaknesses before attackers do and build security programs that cover both technology and people.

 

Cyberattacks Against Major Hedge Funds FAQs

What is voice phishing (vishing)?

Voice phishing is a social engineering attack where criminals use phone calls or voice messages to trick employees into revealing sensitive information, approving authentication requests, or providing system access.

Why are voice phishing attacks increasing?

Attackers have discovered that convincing an employee is often easier than hacking technical vulnerability. Artificial intelligence has also made it easier to create believable conversations and impersonate trusted individuals.

Can multi-factor authentication stop these attacks?

Multi-factor authentication significantly improves security, but attackers often attempt to convince users to approve MFA requests or disclose temporary verification codes. User awareness remains essential.

Are only financial institutions targeted?

No. Healthcare providers, manufacturers, law firms, construction companies, retailers, government contractors, and small businesses are all frequent targets of social engineering attacks.

How often should businesses conduct security awareness training?

Most businesses should provide ongoing training throughout the year rather than relying on a single annual session. Regular phishing simulations and refresher training help employees recognize evolving attack techniques.

Should businesses test employees with social engineering assessments?

Yes. Authorized social engineering assessments provide valuable insight into how employees respond to realistic attack scenarios and identify opportunities for additional training.

How can penetration testing help reduce social engineering risk?

Penetration testing evaluates how attackers could exploit technical weaknesses after gaining initial access, while social engineering assessments evaluate whether employees can recognize and respond appropriately to attempted deception.

What is the biggest lesson from this incident?

Technology alone is not enough. Even businesses with mature cybersecurity programs remain vulnerable if attackers can successfully manipulate employees into granting access.

Cyberattacks Against Major Hedge Funds Conclusion

The recent cyberattacks on major hedge funds show that attackers today are focusing more on people than on software.

Firewalls, endpoint protection, and cloud security remain essential, but businesses must also prepare employees to recognize sophisticated social engineering attempts.

Whether your company handles billions or is a small family business, the lesson is the same.

Your employees are often your first line of defense.

Investing in technical security, employee awareness, and regular security checks builds a stronger cybersecurity program that can handle the changing tactics used by today’s attackers.

 

Schedule a Call

Name*
Please let us know what's on your mind. Have a question for us? Ask away.