Accessibility help Skip to navigation Skip to main content Skip to footer

Hedge funds

Add to myFT

Get instant alerts for this topic

Manage your delivery channels here Remove from myFT

Big US hedge funds targeted by wave of cyber attacks

Point72 and Citadel among firms hit by audio phishing schemes

Two people walk past a large Point72 Asset Management sign outside an office building.Point72 was investigating the incident and trying to determine whether their systems were breached© Bloomberg

current progress 0%

Costas Mourselas, Amelia Pollard and Tom Wilson

Published3 hours ago

Jump to comments section Print this page

Stay informed with free updates

Simply sign up to the Hedge funds myFT Digest -- delivered directly to your inbox.

Several of the biggest hedge funds on Wall Street have been targeted by a wave of cyber attacks, putting the industry on high alert to the risk of vulnerabilities in their software systems.

Billionaire Steve Cohen’s Point72 and Ken Griffin’s Citadel were among the hedge funds that were targeted by audio “phishing” attacks, attempts to obtain private information through phone calls and similar means, in recent days, according to people familiar with the matter.

Millennium Management was also targeted by cyber attacks, according to a person familiar with the matter.

All of the firms run complex risk systems with confidential trading information and manage tens of billions of dollars, making them prime potential targets for cyber criminals.

Point72 was investigating the incident and trying to determine whether their systems were breached, according to one person familiar with the matter. It has contacted law enforcement and hired cyber security experts. The hedge fund also emailed investors on Wednesday to inform them that it did not believe any client information had been stolen.

Citadel did not appear to be breached in the attack, according to other people familiar with the matter. One of the people highlighted that phishing attacks were common, but that the number of attacks had increased recently. All of the firms declined to comment.

Bloomberg first reported the attempted attacks at some of the firms.

At least some of the incidents involved voice phishing scams, in which the perpetrator impersonated a trusted person or colleague through phone calls or other audio communication, according to the people. It was not clear who was behind the attacks, or if they were co-ordinated by a single group.

At one of the hedge funds, cyber criminals impersonated the firm’s help desk, according to one person familiar with the matter. They contacted employees to try to gain login credentials for their authenticator apps, which serve as an additional layer of security in accessing a company’s software system beyond usernames and passwords.

The incidents come as governments and companies are racing to respond to the launch of AI tools that have made it easier for cyber criminals and state-backed groups to hack targets. Frontier AI models, in particular, have supercharged a cyber arms race as malign actors develop new abilities to attack while companies and governments seek new ways to defend themselves.

A cyberdefence group at Google published a report in June detailing a similar series of incidents at law firms and financial institutions, in which the attackers also used phone calls to mimic IT employees.

Wall Street groups have poured resources into beefing up their own cyber security systems in recent years, as AI has heightened the possibility that even unsophisticated actors could successfully hack into a company’s network.

Reuse this content(opens in new window) CommentsJump to comments section

Follow the topics in this article

Add to myFT

Add to myFT

Add to myFT

Add to myFT

Add to myFT

Comments

Close side navigation menu

Search the FTSearch

Subscribe for full access

Read Original at Financial Times