A coordinated wave of cyberattacks has targeted several of Wall Street's largest hedge funds, with hackers using artificial intelligence to impersonate employees and manipulate staff into granting access to sensitive systems, Bloomberg reported on Wednesday.

The attackers attempted to breach information systems at some of the world's biggest hedge funds including Two Sigma Investments, Citadel and Point72 Asset Management, according to people familiar with the matter. Several private equity firms were also targeted as part of the assault.

The attack featured voice phishing, or vishing, in which cybercriminals use technology to mimic voices in phone calls or messages to trick employees into revealing sensitive information or granting access. The attackers allegedly used technology capable of listening to phone calls and then replicating a speaker's voice, tone and phrasing to fabricate convincing fake calls.

Two Sigma Says It Blocked the Attack

Two Sigma, which oversees $75 billion of assets, said it thwarted the attempt to access sensitive data. "Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems," a Two Sigma spokesperson said in a statement.

Point72 Asset Management informed investors on Wednesday that it had been attacked, though the hedge fund's initial indications were that no client information was stolen. The firm told investors it was still reviewing the incident.

Advertisement

Spokespeople for Point72 and Citadel declined to comment on whether hackers have breached their systems.

AI Has Made Attacks Cheaper and Broader

Cybersecurity breaches on Wall Street have surged over the past year, as artificial intelligence tools help bad actors launch attacks relatively cheaply and broadly, said Vinod Paul, president of Align Managed Services, which specializes in helping hedge funds with cybersecurity. "Before they could attack 50 entities in a targeted attack, now they can do 1,000," Paul said.

Will Wilson, CEO of IT security firm Antithesis, argued financial firms benefited for decades from the scarcity of hacking expertise. Modern AI has "commoditized" that skill set, he said, pushing hedge funds and other firms toward urgent security upgrades or serious consequences.

The attack technique resembles tactics used by hacking groups like Scattered Spider, a group that gained notoriety in recent years with high-profile breaches and ransomware attacks against large enterprises, including Las Vegas casino and hotel giants Caesars Entertainment and MGM Resorts in 2023. First emerging in 2022, the group's members displayed a knack for social engineering schemes that allowed them to steal credentials from targeted organizations and gain privileged access into their networks. No attribution has been made in the current campaign.

Regulators Already Moving

The Financial Industry Regulatory Authority launched its Financial Intelligence Fusion Center in March, giving members a channel to share fraud intelligence and coordinate responses to sophisticated threats. A FINRA spokesperson declined to comment on the specific incident but confirmed contact with affected firms.

Advertisement

The incidents highlight the growing risk that scammers or rogue states will harness cutting-edge technologies to scale up attacks, sometimes demanding ransoms to unlock data or systems. In Wall Street's case, that can impact firms and markets handling trillions of dollars in daily transactions.

The three targeted hedge funds collectively manage well over $150 billion in assets. Citadel has more than $67 billion in assets under management as of January 2026. Point72 manages approximately $45.7 billion. The scale of these operations makes them attractive targets for financially motivated hackers, and the reliance on algorithmic trading and complex information systems creates a sprawling attack surface.

The firms have not disclosed what, if any, security vulnerabilities were exploited, or whether the attacks were linked to a single group. It remains unclear who the attackers are, the full methods used in the attacks, and whether any sensitive data has been compromised.

Global companies are battling a surge in AI-powered cyberattacks and ransomware that disrupt operations and steal data. In response, the White House announced a working group earlier this year, uniting AI developers and critical infrastructure operators to share threat intelligence and coordinate cyber defenses.