NEW YORK – Hackers targeted major Wall Street firms and money managers in a series of attempted cyberattacks that relied on phone calls to employees, according to Reuters.
The callers tried to persuade workers to grant access to information systems or disclose other sensitive information, two people familiar with the matter told the news organization. The targets included some of the world’s largest hedge funds and several private equity firms.
Point72 Asset Management told investors that it had faced an attack and said no customer information was stolen, Reuters reported. The attackers also attempted to breach systems at Two Sigma Investments and Citadel, according to the report. Two Sigma did not immediately respond to Reuters, while Citadel and Point72 declined to comment.
The method is commonly called voice phishing, or vishing. It uses a live or recorded call to create urgency, impersonate a trusted person or otherwise push an employee to bypass a normal verification step. Reuters did not establish that the calls in these incidents used cloned voices or other AI-generated audio.
Phone-based social engineering remains effective because it targets the point where technical controls meet human judgment. A convincing caller may ask a worker to approve a login, reset credentials or share information that would not be available through a direct attack on a hardened system.
For companies, the response extends beyond security software. Call-back procedures, independent identity checks, limited privileges and clear escalation paths can reduce the chance that one hurried handoff becomes a broader breach.
