Reports emerged that big Wall Street companies like Point72, Citadel, Millennium Management, Blackstone, and CME just got hit by a wave of cyberattacks like voice phishing attempts. These hackers acted like coworkers or Information Technology (IT) support to trick employees into handing over their passwords or letting them into the system.
At one hedge fund, the callers pretended to be from the IT help desk and tried to grab login info for authenticator apps. Point72 has already reached out to the police and brought in some cybersecurity experts to investigate these cases.

The Wall Street attack method and scope
The attackers used voice phishing, or “vishing,” to act like trusted coworkers and convince staff to hand over login details or grant access to company systems. At one hedge fund, the callers claimed to be from the company’s IT help desk, trying to swipe login info for those authenticator apps that provide a necessary extra layer of security beyond standard passwords.
Point72 told investors it did not believe client information had been stolen. Citadel did not appear to have been breached. It remained unclear who was behind the attacks or whether the incidents were coordinated by a single group.
The broader campaign and industry context
The attacks resemble a broader campaign documented by Google’s Mandiant cybersecurity unit. Between January and May, a financially motivated group tracked as UNC3753 targeted dozens of U.S. legal, professional-services, and financial companies by impersonating IT support staff and persuading employees to install remote-access software. But there is no public evidence linking that group to the hedge fund attacks.
Google said voice phishing accounted for 11 percent of the intrusions it investigated during 2025, making it the second-most common initial route into corporate systems. The available reports do not establish that artificial intelligence (AI) was used in the latest attacks, despite wider concern that voice-cloning tools can make impersonation schemes more convincing.
How to defend against these attacks
The vishing attacks targeting Wall Street expose a fundamental weakness: the human voice channel bypasses traditional security controls. Email gateways and network perimeters can’t inspect a live phone call. Attackers leverage AI voice clones (built from public recordings of executives in earnings calls or interviews) to impersonate trusted figures with alarming accuracy.
Google’s Mandiant unit is warning that the typical time from a successful intrusion to handing off access plummeted from eight hours in 2022 to a mere 22 seconds now.
Companies can basically do three main things to stay safe:
- First, decouple support from speed: revise help desk Key Performance Indicators (KPIs) to prioritize identity verification over average handle time.
- Second, deploy phishing-resistant multi-factor authentication (MFA): transition away from Short Message Service (SMS) codes and push notifications to Fast Identity Online 2 (FIDO2) hardware keys or device-bound passkeys.
- Third, conduct voice-specific training with live simulations that mirror real attacker behavior: AI clones, urgency tactics, and follow-up channels.
The Financial Industry Regulatory Authority (FINRA)’s Financial Intelligence Fusion Center (which was launched in March 2026) gives member firms a safe place to swap info on threats, and regulators are already busy teaming up to figure out how to handle these latest attacks.
So far, these cases show the clear reality: legacy security awareness training, built for email, leaves employees unprepared for an urgent call that sounds exactly like the CEO.



