Major hedge funds fend off coordinated cyberattack campaign using AI-driven phishing tactics
TOP STORY: A number of the world's largest hedge funds were recently targeted in a coordinated cyberattack campaign that relied on AI-enabled voice phishing techniques to try to gain access to internal systems, according to a report by Bloomberg.
Multiple leading hedge funds, including Point72 Asset Management, Millennium Management, Citadel, and Two Sigma Investments, experienced a targeted cyberattack campaign in recent times, as reported by Bloomberg. The sophisticated assault utilized AI-driven voice phishing techniques, aiming to infiltrate the firms' internal systems.
The campaign extended to several private equity entities as well. Point72 informed its investors of the attempted breach, stating that, according to their preliminary assessment, no client data had been breached. Investigations are ongoing at Point72, Millennium, and Citadel, while Two Sigma Investments confirmed the successful blocking of an attempted intrusion.
The cyberattacks revolved around "vishing", or voice phishing, wherein AI is used to mimic trusted voices in phone calls or voice messages, with the intent of extracting sensitive information or gaining system access. The frequency and effectiveness of such attacks have been greatly amplified by the advent of generative AI, making it possible for cybercriminals to launch widespread and convincing campaigns against multiple organizations concurrently.
Vinod Paul, president of Align Managed Services, a cybersecurity firm, highlighted that AI now enables attackers to conduct coordinated assaults on hundreds, or even thousands, of organizations at once, while also creating highly realistic voice impersonations. The incident underscores the growing concern within the financial services sector about the exploitation of AI for carrying out sophisticated cyberattacks.
In June, Google's cybersecurity analysts cautioned about an increase in vishing campaigns targeting professional services firms, such as law firms, with some perpetrators attempting to gain physical access to offices by posing as IT personnel. The Financial Industry Regulatory Authority (FINRA) has been reaching out to member firms concerning the recent attempted breaches, recently establishing the Financial Intelligence Fusion Center to bolster intelligence sharing and coordination on cyber and fraud threats within the securities industry.
Written by urgent.news from Hedgeweek's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
