DATANEWS

Major Wall Street Firms Targeted in Voice-Phishing Cyberattack Wave

Reuters · 2026-08-06

Point72, Citadel, Two Sigma and other major financial firms were reportedly targeted by attackers using phone-based social engineering to pursue credentials and system access.

Why it matters: The campaign shows that social engineering against identity and help-desk processes remains a critical weakness for high-value financial institutions.

Several major U.S. investment firms have reportedly been targeted in a coordinated series of cyberattack attempts using phone-based social engineering.

The firms targeted included Point72 Asset Management, Citadel and Two Sigma Investments, according to Reuters. Attackers allegedly impersonated trusted individuals and attempted to persuade employees to disclose confidential information or provide access to company systems.

Point72 notified investors about the attempted intrusion and said it had found no evidence that customer data was lost.

The Financial Times separately reported that Millennium Management was also targeted and that some callers posed as help-desk or support personnel seeking access to critical software accounts.

The incidents demonstrate why identity has become a central enterprise-security boundary.

Modern financial firms use extensive cloud infrastructure, trading platforms and remote-access systems. Even when those systems are technically secure, an attacker who convinces an employee or support agent to reset credentials may bypass several defensive layers.

AI-generated speech and readily available personal information can make voice-phishing attempts more convincing, although the involvement of synthetic voices in these specific incidents has not been confirmed.

Financial institutions should treat telephone-based password resets, multifactor-authentication changes and privileged-access requests as high-risk transactions requiring independent verification.

The attempted attacks have not been attributed to a specific criminal or state-sponsored group, and available reporting does not establish that the targeted firms suffered material data breaches.

Source and attribution →