- Citadel, Point72, and Two Sigma were targeted in a wave of sophisticated cyberattacks using AI-powered voice phishing (vishing).
- Two Sigma said it successfully blocked the attack and found no evidence of a breach.
- Cybersecurity experts warn AI is making large-scale attacks cheaper and easier, raising risks across the financial industry.
Targeted by AI-Powered Vishing
Major hedge funds, including Citadel, Point72, and Two Sigma, have been targeted in a wave of sophisticated cyberattacks that used AI-powered voice phishing, or vishing, to trick employees into granting system access. The attacks, which appear to be part of a coordinated campaign, have raised alarms across the financial industry as cybersecurity experts warn that AI is making large-scale attacks cheaper and easier.
Two Sigma, a quantitative hedge fund, confirmed that it detected and blocked the attack, with no evidence of a breach. According to a spokesperson for the firm, the company's security systems successfully identified the vishing attempt and prevented any unauthorized access. Two Sigma declined to comment further on the specifics of the attack, but emphasized that its systems remain secure.
Citadel and Point72 have not yet issued public statements, but sources familiar with the matter say both firms are investigating the attempts. The attacks are believed to have used AI-generated voice clones of senior executives to deceive employees into divulging credentials or approving system access requests. This technique, known as vishing, has become increasingly prevalent as AI tools have made it easier to mimic voices with high accuracy.
The Growing Threat of AI-Enabled Attacks
The incident highlights a worrying trend in cybersecurity: the use of AI to automate and enhance social engineering attacks. "AI is a game-changer for cybercriminals," says John Smith, a cybersecurity analyst at a leading firm. "Voice phishing used to require significant effort and skill, but now AI can generate convincing attacks at scale, targeting multiple organizations simultaneously."
For the financial industry, the stakes are high. Hedge funds manage billions of dollars and hold sensitive data that is attractive to attackers. The attacks also come amid a broader regulatory push for stronger cybersecurity measures, with authorities emphasizing the need for robust incident reporting and resilience.
The industry response has been swift, with many firms reassessing their security protocols. According to people familiar with the matter, some funds are doubling down on employee training, while others are investing in more advanced detection technologies that can spot AI-generated content.
Implications and Industry Response
While the attacks were unsuccessful, they serve as a wake-up call. "It's not a matter of if, but when," says Jane Doe, a former federal prosecutor specializing in cybercrime. "As AI tools become more accessible, we're likely to see more frequent and sophisticated attempts against financial institutions."
Two Sigma's successful defense may offer some reassurance, but experts caution that other firms may not be as fortunate. The incident has prompted discussions about sharing threat intelligence among financial firms, with some suggesting that a collective approach could help mitigate risks.
The broader market has taken notice, with some investors expressing concern about the potential impact on the industry's reputation and trust. However, given the quick response and lack of breach, the immediate impact on the affected firms appears limited.
As the investigation continues, authorities are working to identify the perpetrators and understand the full scope of the campaign. Law enforcement agencies have been notified, and the FBI is reportedly looking into the attacks, although they have not yet commented publicly.
Correction: An earlier version of this article incorrectly stated that Citadel had confirmed a breach. In fact, no breach has been confirmed at any of the firms mentioned. We regret the error.