Hedge Funds Targeted by Vishing: Inside the Wave That Hit Citadel, Two Sigma and Point72

Vishing
Summarize with:
Vishing Google Report

On August 5, 2026, several of the world's largest hedge funds were targeted in a coordinated wave of voice phishing. No malware. No zero-day. Attackers picked up the phone and called employees. Vishing is now a campaign-grade initial access technique aimed at the most security-mature firms in finance. Here is what happened, and what to change this quarter.

Key Takeaways

  • Attackers ran a coordinated vishing campaign against multiple top-tier hedge funds and private equity firms in early August 2026.
  • Two Sigma blocked the attempt. Point72 told investors it was attacked with no initial sign of client data theft. Citadel and Millennium declined to comment.
  • Sources describe technology used to mimic voices. AI-based voice deepfakes may be implicated.
  • FINRA has contacted member firms, which turns this from news into a documentation question for regulated entities.
  • Vishing intrusions rose 134% between 2024 and 2025, and H1 2026 doubled H2 2025.
  • The highest-value control is procedural: out-of-band callback to a pre-registered number for any voice request touching money, credentials, or access.

What happened: vishing fury on hedge funds

According to Bloomberg, threat actors recently launched a coordinated vishing campaign targeting employees at some of Wall Street's largest investment firms. Attackers impersonated trusted contacts over the phone to trick employees into revealing sensitive information or granting system access.

The targets included Citadel, Two Sigma, Point72, Millennium Management, and several private equity firms, some of the world's most security-conscious financial institutions. The attacks demonstrate that even organizations with mature cybersecurity programs remain vulnerable to sophisticated social engineering.

So far, there is no public evidence that the campaign resulted in a successful breach. Two Sigma said it detected and contained the attack with no impact to its systems or data. Point72 also confirmed it was targeted, stating that its initial investigation found no client information had been compromised.

The incident prompted a rapid response from regulators. FINRA alerted member firms to the attempted intrusions through its Financial Intelligence Fusion Center, launched in March 2026 to share threat intelligence and coordinate responses across the financial sector.

Why hedge funds

Concentrated authority:
Small teams move very large sums. One treasury or operations employee can often initiate transfers that would need committee approval elsewhere.

Legitimate urgency culture:
Urgent out-of-band requests from senior staff are routine here. The signal that would raise an alarm elsewhere is business as usual.

Lean help desks with reset authority:
IT support with MFA reset rights is often small or outsourced. One compromised agent yields identity-layer access without touching an endpoint.

The Consequences of the Rising Vishing Threat

This wave of coordinated vishing attacks is the visible end of a trend line that has been steepening for two and a half years.

Crowdstrike 2026 Threat Hunting Report

The CrowdStrike 2026 Threat Hunting Report gives three reasons why vishing keeps growing, and each applies directly to a fund environment.

It bypasses traditional controls. No attachment, no link to rewrite, no binary to flag. Your email security stack has no visibility into a phone call.

It exploits the human factor harder. Live human-to-human interaction is more persuasive than an email. Attackers typically impersonate IT staff, citing a trivial support issue as pretext.

It leaves almost nothing behind. Vishing produces far fewer forensic artifacts than phishing or smishing, making post-incident investigation materially harder.

Voice synthesis removes the operator-hours constraint that has capped this technique so far. The curve above is the pre-AI baseline.

The chain to plan against

  1. Vishing call lures the target to an adversary-in-the-middle page, usually on a personal unmanaged device chosen because it sits outside security visibility.
  2. Credentials and MFA response are captured.
  3. The adversary authenticates through a residential proxy matching the user's geolocation.
  4. The adversary enrolls their own MFA device for persistence.
  5. Direct SaaS access follows. No malware, no lateral movement, no privilege escalation.

In one February 2026 case, hunters detected the activity four minutes after the call and the customer evicted the adversary within twenty. That is your response window.

What financial services firms should do now

A vishing call in isolation cannot be detected by enterprise tooling. The controls that work are procedural and behavioral.

Priority Control Owner
P0 Out-of-band callback to a pre-registered number for any voice request involving money movement, credential reset, or access change Treasury, IT help desk
P0 Policy that employees ignore unsolicited calls to personal devices from anyone claiming to be IT Security, HR
P1 Dual authorization and delay windows for transfers above threshold Finance, treasury
P1 Hardened identity verification for help desk MFA resets IT operations
P1 Behavioral anomaly monitoring on outbound transfers Fraud, security operations
P2 Alerting on new MFA device registration and anomalous session geolocation Security operations
P2 Tabletop exercise simulating a successful impersonation call CISO, IR lead

Callback is the control that matters most. An attacker can clone a voice, spoof caller ID, and hold a fluent conversation under pressure. They cannot answer the number already on file.

Training is the other half. Staff who have already taken a convincing simulated vishing call recognize the real one faster, because recognition comes from exposure, not instruction.

Our full defensive blueprint covers the 30-60-90 day rollout, role-by-role targeting, and realistic susceptibility benchmarks for finance populations.

Read the CISO playbook: AI vishing attacks and how to defend finance teams →

Test and train on real and current attack patterns

Simulate realistic vishing attacks
Enterprise-scale voice campaigns with real-time voice AI, caller profile control, and scenarios that mirror live attacker pretexts, including IT impersonation and treasury operations reviews.
Train on deepfake impersonations
Realistic deepfake Teams, Google Meet or Zoom calls with executive impersonation, so finance staff meet a synthetic CFO in a controlled exercise rather than on a live wire request.
Train on the latest phishing tactics
Multi-step tactics like ClickFix lures and AI-enhanced phishing, covering cross-channel patterns where an email sets up a call, or a call sets up a link.

After a publicly reported sector-wide campaign, the investment committee will not ask whether you run training. It will ask whether the targeted population was tested against this specific technique, and what the results were.

Most awareness programs run on latency. A technique appears in the wild, hits the press, and enters the training calendar six to twelve months later. Employees train on last year's attacks. Arsen turns emerging social engineering attacks into hands-on training within 30 days, before they reach your workforce.


See how your team handles the call

The funds named in this campaign found out under real conditions. You do not have to. Test your finance, treasury and help desk populations against the techniques in circulation right now, and get the evidence your board will ask for.

See how Arsen simulates real vishing attacks →



Can your team spot a vishing attack?

Test them and find your blind spots before attackers do.

Don't miss an article

No spam, ever. We'll never share your email address and you can opt out at any time.