Major Hedge Funds Hit by Coordinated AI Voice-Phishing…
Wall Street hedge funds including Two Sigma, Citadel, and Point72 were targeted in a coordinated AI-powered voice-phishing campaign aimed at gaining…
- Incident date
- Aug 2026
- Target
- Two Sigma Investments, Citadel, and Point72 Asset Management
On August 5, 2026, a wave of sophisticated cyberattacks targeted several major Wall Street hedge funds, utilizing artificial intelligence to impersonate employees and attempt unauthorized access to sensitive information systems. The campaign affected firms including Two Sigma Investments, Citadel, and Point72 Asset Management, as well as several private equity firms, highlighting the rising threat of AI-driven social engineering in the financial sector.
What happened
The attackers employed voice phishing, or vishing, to manipulate staff into revealing credentials or granting system access. The technology used allowed the perpetrators to listen to live phone calls and synthesize a speaker's voice, tone, and specific phrasing in real-time, creating highly convincing fraudulent communications. This technique echoes the social engineering tactics previously associated with groups like Scattered Spider, which gained notoriety for large-scale breaches in 2023.
Two Sigma, which manages $75 billion in assets, confirmed that their security team successfully thwarted the attempt and reported no impact on their data or systems. Point72 Asset Management acknowledged being targeted and informed investors that, based on initial reviews, no client information had been compromised, though the firm continued to assess the incident. Both Citadel and Point72 declined to comment on whether their systems had been breached. While the total assets under management for the three primary firms exceed $150 billion, regulators and security experts note that the commoditization of AI tools has enabled attackers to scale these campaigns from dozens of targets to over a thousand simultaneously. No formal attribution for the campaign has been made, and the full extent of the attempted breaches remains under review.