Forward Features Calendar

Share this article?

Newsletter

Like this article?

Sign up to our free newsletter

Major hedge funds fend off coordinated cyberattack campaign using AI-driven phishing tactics

Related Topics

A number of the world’s largest hedge funds were recently targeted in a coordinated cyberattack campaign that relied on AI-enabled voice phishing techniques to try to gain access to internal systems, according to a report by Bloomberg.

The report cites unnamed people familiar with then matter as revealing that Point72 Asset Management, Millennium Management, Citadel and Two Sigma Investments, were all among the firm’s targeted. Several private equity firms were also reportedly included in the wider campaign.

Point72 notified investors that it had detected an attempted breach and said its preliminary assessment indicated that no client information had been compromised. The firm is continuing to investigate the incident. Millennium, Point72 and Citadel declined to comment publicly.

Two Sigma confirmed that it had successfully blocked an attempted intrusion.

The attacks reportedly centred on voice phishing, or “vishing”, in which cybercriminals use artificial intelligence to imitate trusted voices during phone calls or voice messages in an effort to persuade employees to disclose sensitive information or provide system access.

Cybersecurity specialists say such attacks have become significantly more scalable with advances in generative AI. Vinod Paul, president of managed cybersecurity provider Align Managed Services, said AI now enables attackers to launch targeted campaigns against hundreds or even thousands of organisations simultaneously, while also creating increasingly convincing voice impersonations.

The latest incidents come amid heightened concern across the financial services industry over the use of AI to automate sophisticated cyberattacks. In June, Google’s cybersecurity researchers warned of a rise in vishing campaigns targeting professional services firms, including law firms, with some attackers even attempting to gain physical access to offices by posing as IT personnel.

The Financial Industry Regulatory Authority (FINRA) has also been communicating with member firms regarding the recent attempted breaches. Earlier this year, the regulator established its Financial Intelligence Fusion Center to improve intelligence sharing and coordination on cyber and fraud threats affecting the securities industry.

Like this article? Sign up to our free newsletter

FEATURED

MOST RECENT

FURTHER READING

Please select one of the below *
Notify Me
Firm Type *
Please select below
Terms & Conditions *
Privacy Policy *