Point72 Cyberattack: Voice Phishing Hits Wall Street Funds

Major hedge funds targeted by AI-boosted voice phishing campaign

The recent Point72 cyberattack has put the spotlight on voice phishing threats targeting some of Wall Street’s most prominent hedge funds. In early August 2024, attackers attempted a sophisticated vishing campaign against Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. This incident underscores the growing risk posed by AI-driven social engineering in the financial sector.

Details of the Point72 Cyberattack and Voice Phishing Campaign

On 5 August 2024, Point72 Asset Management notified its investors of a cyberattack attempt. Attackers used voice phishing (vishing) techniques to contact employees at Point72 and other major hedge funds. The goal was to trick staff into revealing sensitive information or providing access to internal systems. Although Point72 confirmed that no client data was compromised, the campaign highlighted the evolving tactics used by cybercriminals.

According to reports, the vishing campaign extended to several leading firms:

  • Point72 Asset Management (incident confirmed, no data loss reported)
  • Millennium Management (targeted, impact undisclosed)
  • Two Sigma Investments (targeted, impact undisclosed)
  • Citadel (targeted, impact undisclosed)

Point72 informed investors but declined public comment. For the other firms, the full extent of the attempted breaches remains confidential. The attacks were first reported by Bloomberg, with additional coverage emerging from Reuters and cybersecurity analysis platforms.

How the Voice Phishing Attack Worked

The attackers employed vishing, a social engineering technique where criminals impersonate trusted parties, most often IT support or helpdesk staff. Their aim was to persuade employees to share credentials, security codes or grant access to sensitive systems. Unlike traditional phishing, which relies on email, vishing leverages phone calls to create a sense of urgency and trust.

Key characteristics of the attack included:

  • Calls originating from spoofed numbers appearing to be internal or official
  • Impersonation of IT support personnel, with urgent requests for login details or remote access
  • Use of AI-enhanced voice generation to mimic accents, tones or speech patterns of legitimate staff
  • Attempts to bypass multi-factor authentication (MFA) by persuading staff to share codes or approve push notifications

Security experts noted that these attacks did not exploit software vulnerabilities but targeted human behaviour, exploiting trust and urgency. Reports suggest that the techniques used were similar to those previously employed by the cybercriminal group known as “Scattered Spider,” which has successfully targeted large organisations using social engineering and vishing tactics.

AI’s Role in Increasing Attack Sophistication

One of the main concerns raised by the Point72 cyberattack is the use of artificial intelligence to enhance the effectiveness of social engineering. AI-powered voice synthesis enables attackers to convincingly impersonate real employees or support staff. This increases the chance that a targeted staff member will believe the call is genuine and comply with malicious requests.

Recent research by Google’s cybersecurity team, as well as ongoing threat intelligence from other vendors, confirms a broader pattern: financially motivated attackers are increasingly using AI to automate and personalise their attacks. In this incident, the attackers’ ability to spoof voices and manipulate phone systems meant that even organisations with strong technical controls could find their defences circumvented by social engineering.

Notably, the attackers targeted staff with access to critical systems or sensitive data, aiming to obtain credentials that would allow further penetration into financial networks. Although this campaign did not result in reported data loss at Point72, the broader risk to similar organisations is significant, especially as AI tools become more accessible to threat actors.

Timeline and Exploitation Status

  • Late July–Early August 2024: Attackers initiate vishing calls to employees at Point72, Millennium Management, Two Sigma Investments, and Citadel.
  • 5 August 2024: Point72 informs investors of the attempted breach, stating no client data was compromised.
  • 6–7 August 2024: Media reports surface, with Bloomberg and Reuters providing additional details and confirmation from anonymous sources.
  • Ongoing: No confirmed reports of successful data theft or unauthorised access at any of the targeted firms. Investigations and reviews of helpdesk procedures and staff training are underway.

As of this writing, the attack appears to have been contained, with no public disclosure of breached accounts or stolen information. However, the campaign demonstrates the ongoing threat to financial organisations from vishing and AI-enhanced social engineering.

Why This Attack Matters for Financial Services

The Point72 cyberattack is a stark reminder that even highly regulated, security-conscious organisations are vulnerable to social engineering. The combination of AI-driven tools and advanced vishing tactics increases the likelihood of successful intrusions, particularly where helpdesk, call-back verification and MFA processes may be weak or inconsistently applied.

Financial services firms hold vast amounts of sensitive data and manage significant assets, making them high-value targets. This campaign illustrates how attackers are adapting to technological defences by focusing on human vulnerabilities.

Immediate Actions for Organisations

  • Review and reinforce helpdesk and call-back verification procedures for sensitive requests
  • Test and harden MFA workflows against social engineering bypass attempts
  • Deliver targeted security awareness training focusing on vishing and AI-enhanced voice scams
  • Monitor and investigate any suspicious helpdesk or IT-related calls

While no client data was compromised in this incident, the financial sector is likely to see continued attempts using these methods.

Originally reported by thecyberexpress.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call