icon
Have any questions?
Call: 09668200222
Cyber Attacks Cyber Security News & Events

AI Powered Vishing: Inside the Cyberattack Wave That Hit Wall Street’s Biggest Hedge Funds

How a Weeks-Long Voice Phishing Campaign Tested Wall Street’s Biggest Names

Wall Street street sign symbolizing AI-powered vishing attacks targeting major hedge funds.
Wall Street became the focal point of an AI-powered vishing campaign targeting top hedge funds.

In the first week of August 2026, some of the biggest names in global finance found themselves under attack. Hackers targeted Point72 Asset Management, Two Sigma Investments, Citadel and Millennium Management. Together, these four firms manage hundreds of billions of dollars. The attackers used AI-powered voice phishing to trick employees into handing over system access.

Reuters broke the story on 5 August 2026. Within a day, it became clear the hedge fund attacks were only the visible tip of a much larger campaign. The attackers had already reached over two hundred organisations across finance, law and technology.

This blog looks at what investigators have confirmed so far. It explains what artificial intelligence changed about the attack. And it covers what this means for hedge funds, everyday investors and enterprises watching from a distance.

What Happened: A Timeline

  • Roughly five weeks before the story broke, Google’s Threat Intelligence Group and independent researchers started tracking a coordinated voice phishing campaign. They later linked it to threat clusters researchers call Redact, Pink, Falcon and Helix.
  • 5 August 2026: Reports emerge that hackers launched a wave of sophisticated attacks on Wall Street firms in recent days, citing people familiar with the matter.
  • Point72 Asset Management tells its investors it was attacked. Its initial review finds no stolen client information, though the review continues.
  • Two Sigma Investments manages about 75 billion dollars in assets. The firm confirms it detected and blocked an attempted intrusion. Nothing suggests its systems or data were affected.
  • Citadel and Millennium Management decline to confirm or deny whether hackers compromised their systems.
  • 6 August 2026: Fortune and other outlets report that several private equity firms were also targeted. FINRA has been in touch with member firms about the attempted breaches.
  • 7 August 2026: Further reporting shows the campaign reached well beyond hedge funds. It touched private equity firms Blackstone, KKR, Apollo and Bain Capital, exchange operator CME Group, and ratings agency Moody’s. Law firms Paul Hastings and Greenberg Traurig were hit too, along with consumer technology companies including Uber and Zillow.

AI Powered Vishing_Background_image1

How the Attack Actually Worked

Security teams call this technique vishing, short for voice phishing. Attackers called employees on their personal cell phones. They posed as internal IT help desk staff and directed employees toward convincing fake login pages. These pages harvested passwords and one-time multi-factor codes in real time.

In several reported cases, attackers appear to have used AI voice tools to mimic the tone and phrasing of a real colleague. This made the calls far more convincing than the generic tech support scam of a few years ago.

This is social engineering, not a technical exploit. No firewall or antivirus programme stops it, because the attacker isn’t breaking code. They are persuading a person.

Ransom demands reportedly ranged from roughly 750,000 to 3 million dollars per incident. Researchers have traced close to 10 million dollars in bitcoin to a single linked wallet.

Who Is Behind It

Multiple research teams have linked the campaign to extortion-focused threat actors. Some reports point to a cluster tracked as UNC6671, associated with the BlackFile extortion brand. Google’s Threat Intelligence Group separately names clusters it calls Redact, Pink, Falcon and Helix. Researchers say these groups pivoted toward private equity and legal firms this year, hunting for high-value data to hold for ransom.

Attribution in campaigns like this rarely settles quickly. Different research teams often describe different pieces of the same larger operation. But one thing stays consistent across every report: patient, well-resourced social engineering aimed squarely at people, not systems.

At a Glance

Detail What’s Known So Far
Attack type AI-powered voice phishing (vishing) campaign
Primary hedge fund targets Point72, Two Sigma, Citadel and Millennium Management
Wider campaign Reportedly touched 200+ organisations, including Blackstone, KKR, Apollo, Bain Capital, CME Group, Moody’s, and several law and technology firms
Entry method Fake IT help desk calls directing employees to spoofed login pages
Data stolen Point72 and Two Sigma report no client data stolen so far; full scope still under review
Ransom demands reported Roughly 750,000 to 3 million dollars per incident
Regulatory response FINRA’s Financial Intelligence Fusion Center engaged with member firms

Why This Isn’t Just a Wall Street Problem

This campaign didn’t stay inside the finance industry, and that’s the real headline. According to Google’s cybersecurity unit, the same vishing playbook already hit law firms and professional services companies earlier in 2026. Attackers have separately used related techniques against water utilities and consumer platforms.

Artificial intelligence hasn’t invented a new category of crime. It has removed the cost and the skill barrier from an old one. A campaign that once needed a small, highly trained crew of social engineers can now run with a much smaller team leaning on generative voice tools. It operates at a scale once reserved for mass phishing emails. Industry experts note that attackers who could once realistically target fifty organisations in a campaign can now target a thousand.

The Impact

For Hedge Funds and Financial Institutions

Even an unsuccessful attack carries real cost. Firms lose hours to investigation, investor communication and regulatory scrutiny. Reputational damage hits the moment a firm’s name appears beside the word “breach,” confirmed or not.

Firms that handle material non-public information face special exposure. A single compromised credential can, in theory, reach trading positions, client portfolios or merger-related data long before any ransom demand arrives.

For the Everyday Citizen and Investor

Most people reading this don’t work at a hedge fund. But many have money that flows through one indirectly, through a pension fund, an insurer’s investment arm, or a mutual fund that allocates capital to these managers.

When hackers probe a financial institution’s systems at this scale, the risk doesn’t stop at large portfolios. It reaches the infrastructure that quietly manages retirement savings and institutional capital for millions of ordinary people.

And the vishing technique itself doesn’t stay confined to Wall Street phone lines. Scammers already use the same AI voice cloning tactics in calls to regular bank customers. They impersonate relatives, bank officials or IT support, which makes the personal risk at least as real as the institutional one.

What You Should Do Right Now

For Employees at Financial or Enterprise Firms

  • Treat any unexpected call from IT support with suspicion, even if the caller already knows internal details. Verify through a separate, known channel before you act.
  • Never enter your password or a one-time MFA code into a page you reached through a link sent during a phone call.
  • Report the call to your security team immediately, even if you’re not sure it was real. Early reports let a SOC catch a live campaign in time.

For Everyday Investors and Citizens

  • Ask your bank, pension provider or investment platform whether the attack affected them, and how they would notify you if something changed.
  • Stay alert to unusually convincing calls claiming to be from your bank or broker. AI voice cloning is no longer a Wall Street-only problem.
  • Watch your statements over the coming weeks. Large campaigns like this one sometimes surface consequences well after the original attempt.

Threatsys Perspective

As a cybersecurity company working across red teaming, cloud security and managed detection for financial and enterprise clients, we see this incident as a preview. Social engineering is heading everywhere, not only toward Wall Street. Two things stand out to us.

First, the technical controls at every named hedge fund reportedly worked exactly as intended. Two Sigma’s outcome is the instructive one here. The attack didn’t fail on its own; a trained employee, backed by a monitored security operations team, recognised the attempt and shut it down before it went anywhere. That’s not luck. That’s what a mature detection and response programme is built to do.

Second, the firms that stayed quiet about the full scope show why disclosure discipline matters just as much as technical defence. Attackers running a sector-wide campaign count on the fact that most victims won’t compare notes quickly. A well-rehearsed incident response plan, tested through red teaming and tabletop exercises, closes that gap between an attempted breach and a coordinated, sector-wide response.

How Threatsys Can Help

 

 

This incident reads like a checklist of the gaps we help organisations close every day.

  • Red Teaming: We simulate this exact kind of vishing and social engineering campaign against your own employees, safely and under controlled conditions. We find the gaps before an attacker does.
  • VAPT across Web, Cloud and API: Vulnerability assessment and penetration testing covers your full attack surface, not just the front door.
  • SOC 2 Compliance: We help financial and enterprise clients build and evidence the access controls, monitoring and incident response processes that SOC 2 audits require.
  • Managed Cybersecurity Solutions: Ongoing monitoring and threat management catch and contain a live social engineering attempt, the way Two Sigma’s own team caught theirs.
  • Mobile Device Management(MDM) : Since these attacks specifically target personal and work mobile phones, a proper MDM policy limits how much a compromised device or number can actually reach.
  • Data Loss Prevention(DLP): Even if an attacker gets in, DLP controls slow or stop sensitive data from actually leaving the network.
  • SOC and SIEM: A staffed Security Operations Centre, backed by SIEM correlation, turns an employee’s strange phone call into a caught and shut down intrusion attempt within minutes, rather than a discovery made weeks later.

The Bigger Lesson

The most sophisticated technical defences in the world can be routed around by a convincing phone call. That’s true if the people answering it aren’t trained and supported to question it. This campaign didn’t succeed by breaking encryption or exploiting a hidden software flaw. Where it succeeded, it did so by asking politely and confidently for a password. That’s the uncomfortable truth artificial intelligence has amplified: the weakest link in most security programmes was never the code. It was always the conversation.

Conclusion

The full scope of this campaign is still emerging. Investigators don’t yet know how many of the two hundred-plus targeted organisations were actually compromised, or how much data or money changed hands. But one thing is already clear: AI has made social engineering cheaper, faster and more convincing. No institution, however well-resourced, is immune to a well-timed phone call.

For hedge funds, enterprises and individual investors alike, the response has to move beyond firewalls and antivirus software. It has to reach the human layer of security: trained people, tested processes, and a team watching in real time.

That’s where Threatsys works, and we’d be glad to help you get ready before your organisation becomes the next name in a headline like this one.

Contact US Threatsys

Stay secure, Stay aware with Threatsys.

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *