-
Hackers used phone calls, not hacking tools, to target big Wall Street investment firms.
-
Point72, Citadel, Two Sigma, and Millennium Management were among the named targets.
-
The scam tricked workers into giving away access, instead of breaking through security software.
Hackers hit some of Wall Street’s biggest investment firms with a wave of phone scams. They skipped hacking tools and malicious software.
Instead, they called staff directly. The callers tried to trick workers into handing over private data. Some calls aimed to gain entry into company systems.
Callers target Point72, Citadel, and other firms
Reuters reported the attacks ran for several days. They hit some of the largest hedge funds and private equity firms in the world. The callers tried to fool staff into sharing secret details. Some employees almost approved access that they should have blocked.
Point72 Asset Management, Citadel, and Two Sigma Investments were named in the reports. Point72 told its investors it caught an attempted attack. The firm said it found no proof that client data leaked out. Citadel chose not to comment on the matter. Two Sigma did not answer requests for comment right away.
The Financial Times also named Millennium Management as a target. One caller pretended to work on the firm’s IT help desk. The caller tried to get an employee to share login codes. Those codes could have opened the door to company systems. Point72 also hired cybersecurity experts. The firm reported the incident to the police too.
Attackers focus on people, not software
The scam did not rely on breaking software. It did not exploit any technical flaws either. Instead, it targeted people directly. Attackers used voice phishing, often called “vishing,” to trick staff into giving up access on their own.
According to Reuters, security experts say financial firms deal with hacking attempts often. But phone scams remain one of the most effective tricks. They work because they target human trust, not computer code.
The value of stolen personal data is underscored by California’s new law imposing $200 daily fines on data brokers that ignore deletion requests, aiming to reduce the commercial availability of the very information criminals seek in vishing scams.
Reuters also noted that no known hacking group has claimed the attacks yet. Experts pointed out that similar tricks have shown up before, tied to a hacking group known as Scattered Spider. But so far, nobody has linked that group to this specific campaign.
The Financial Times said the scam matches methods described in a recent Google threat report. Google’s team warned that money-driven hackers increasingly use convincing phone tricks. They target law firms and financial companies this way.
The report also said newer AI tools now let criminals fake voices that sound very real. That makes the scam calls much harder for workers to catch.
Financial firms face growing online risks
Investment firms remain top targets for hackers. They manage large sums of money. They also hold sensitive client details and private business plans. That combination draws criminals who want to steal data or break in without permission.
According to Reuters, financial companies keep facing several types of threats. These include ransomware, stolen passwords, and phishing scams. Many of these scams now use artificial intelligence to seem more convincing.
Reuters also reported that the White House set up a new working group earlier this year. The group brings together AI companies and operators of key infrastructure. Its goal is to share information faster. It also aims to build stronger defenses against new online threats.
The recent scam calls do not appear to have caused a major data leak. Still, the attempts show that criminals keep trying to trick people, even at firms with strong defenses. Rather than breaking into computers directly, they try to convince workers to help them get in.
These incidents also show why checking someone’s identity still matters. This is true especially during phone-based support requests. Both Reuters and the Financial Times reported that callers pretended to be trusted staff members. Their goal was to trick workers into revealing information that could unlock internal systems.
This wave of scam calls serves as another warning for the finance world. Phone-based tricks remain a serious risk. As criminals sharpen their methods and use smarter technology, firms will likely keep training staff. They will also tighten identity checks. Both steps aim to lower the risk of similar scams happening again.