According to Bloomberg, several of the world’s largest hedge funds, including Citadel, Millennium Management, Two Sigma Investments, and Point72 Asset Management, have been targeted in a sophisticated phishing campaign involving artificial intelligence and voice phishing (vishing).

According to the report, several private investment firms were also targeted in the campaign. However, their identities have not been disclosed for confidentiality reasons.
According to two people familiar with the matter, Point72 Asset Management informed its investors on Wednesday that it had been targeted in a cyberattack attempt.
The global asset management firm said the attackers did not gain access to client data. Two Sigma also confirmed that it successfully blocked the attack, although its investigation into the incident is still ongoing.
“Our security team responded quickly to an attempted attack targeting Two Sigma and other investment managers, and we have no indication that our data or systems have been compromised,” Two Sigma said in a statement.
“We continue to monitor the situation closely,” a company spokesperson added.
Citadel and Millennium Management have not publicly commented on the reported attacks.

The combined assets under management (AUM) of the targeted Wall Street firms are substantial:
Millennium Management: $77.5 billion
Two Sigma: $75 billion
Citadel: $67.6 billion
Point72: $50.7 billion
According to Bloomberg, unknown attackers have spent the past several days targeting employees at financial firms using AI-generated voices. This form of social engineering is known as vishing, or voice phishing.
During these attacks, scammers place phone calls or send voice messages in an attempt to trick employees into revealing usernames, passwords, one-time authentication codes, or other sensitive credentials. Once obtained, this information can be used to gain unauthorized access to a company’s internal systems.

Attackers often use artificial intelligence to clone the voices of executives or impersonate IT support staff. During these calls, they attempt to convince employees to reset their passwords, share one-time authentication codes, or approve fraudulent requests for access to corporate systems.
According to Black Kite’s 2026 Financial Services Cybersecurity Report, investment firms became cybercriminals’ primary targets in 2025, overtaking traditional banks as the most frequently attacked organizations in the financial sector.
Black Kite reports that ransomware attacks against the financial sector increased by 30% in 2025. In the first quarter of 2026 alone, that figure rose by another 76%. Investment firms accounted for approximately 40% of all publicly disclosed cybersecurity incidents across the financial industry.