Urgent.News

What's breaking now, across thousands of outlets.

Tech

Major hedge funds targeted in wave of attempted cyberattacks

Cyber criminals attempted using voice phishing to mimic voices in phone calls to gain access to sensitive information at major hedge funds.

Major hedge funds targeted in wave of attempted cyberattacks

Recent days have witnessed a barrage of sophisticated cyberattacks on major Wall Street firms, as hackers targeted the information systems of prominent money managers, according to sources familiar with the situation. Point72 Asset Management disclosed on Wednesday that it had been targeted, although the firm initially reported no client data was stolen, according to one of the people who spoke on the condition of anonymity.

The company stated they were still investigating the incident. Attackers also attempted to breach the systems of other high-profile hedge funds, including Millennium Management, Two Sigma Investments, and Citadel, as well as several private equity firms, according to the sources. The assault utilized voice phishing, or vishing, a technique where cybercriminals use technology to impersonate voices in phone calls or messages to trick employees into disclosing sensitive information or granting them access.

Two Sigma, which manages $75 billion in assets, stated they successfully thwarted the vishing attempt, assuring there was no indication of any impact to their data or systems. They are closely monitoring the situation. Spokespeople for Millennium, Point72, and Citadel declined to comment. The surge in cybersecurity breaches on Wall Street has been on the rise over the past year, as artificial intelligence tools enable bad actors to launch attacks at a relatively lower cost and on a larger scale, said Vinod Paul, president of Align Managed Services, a firm specializing in cybersecurity and IT for hedge funds.

"Whereas before they could target 50 entities in a targeted attack, now they can do 1,000," Paul explained. "Hackers can also intercept phone calls and mimic the voice, tone, and phrasing of the speakers to create fraudulent calls." In June, Google's cybersecurity team published a blog post warning of a wave of attacks targeting law firms and other professional services companies, including vishing techniques and instances of individuals posing as IT workers at corporate offices.

The Financial Industry Regulatory Authority (Finra), which oversees broker-dealers and securities professionals, has been in contact with member firms about recent attempted breaches, as reported by a separate source with knowledge of the matter. Finra established the Financial Intelligence Fusion Center in March, a secure platform for sharing intelligence about fraud threats and coordinating responses, as a response to the escalating cyber and fraud risks targeting financial services firms.

A spokesperson for Finra declined to provide further comment. These incidents underscore the growing danger that scammers or rogue states may leverage cutting-edge technologies to scale up attacks, sometimes demanding ransoms to regain control of data or systems. In Wall Street's context, this could significantly affect firms and markets that handle trillions of dollars in daily transactions.

Despite the possible lack of connection, this wave of attacks occurred as US authorities were simultaneously tackling cyberattacks on water systems in several states, raising concerns about potential links to Iran. Historically, the financial industry managed to evade stringent software protocols due to the specialized and scarce skillset required for executing attacks, according to Will Wilson, CEO of Antithesis, a company that assists businesses in identifying and rectifying IT vulnerabilities.

"The alarming aspect of modern-day AI systems is that they have made it possible to execute attacks on a large scale, making it accessible to everyone," Wilson stated. "Everyone needs to seriously enhance their cybersecurity measures. Otherwise, they will face serious consequences."

Written by urgent.news from Fortune's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at fortune.com →

More in Tech

One Extra Slash: Hunting a Windows Path Bug Down to a Single Formatter

This is my entry for DEV's Summer Bug Smash — Smash Stories. Not every good bug is an epic. Some of them are one character long, and the interesting part is entirely in the hunt.

  • Single extra slash in Windows file path caused by formatter
  • Bug missed initially due to no error in path handling
  • Issue identified by comparing raw bytes with processing code

Zig's Io.Threaded is Neat

  • Zig's std.Io.Threaded offers concurrency through blocking syscalls
  • Features deterministic parallelism with independent problem partitions
  • Practical cancellation mechanism allows reliable syscall cancellation

Opus 5: Delete your CLAUDE.md?

Last week Y Combinator posted an interview with Boris Cherny, the engineer who built Claude Code, about the new Opus 5 release ( the full talk ).

  • Anthropic reduced system prompt in Claude Code by over 80% for Opus 5.
  • Engineers suggested deleting CLAUDE.md, skills, and hooks for non-agentic users.
  • Ablation process tested impact of each line in the compressed instruction file.

More from Thursday 6 August →