Hackers have attempted a series of sophisticated cyberattacks on major Wall Street money managers and financial services firms in recent days, targeting their information systems, according to Bloomberg News.
The targets included several private equity firms and some of the world's largest hedge funds, such as Two Sigma Investments, Citadel, and Point72 Asset Management.
The hacking attempts involved audio phishing schemes, where cybercriminals used phone calls to try to trick employees into handing over sensitive information or granting access.
The phone-call tactic has been used successfully by 'Scattered Spider,' described as a loose-knit group of young hackers.
Point72 Asset Management told investors on Wednesday that it had faced an attack from hackers, but indicated that no customer information was stolen.
Citadel and Point72 Asset Management declined to comment on the matter. Two Sigma Investments, Balyasny, and Millennium did not immediately respond to requests for comment.
Rising Threat Landscape
Cybersecurity experts state that attempts by hackers to break into major financial institutions are routine. This occurs amid a surge in AI-powered cyberattacks and ransomware that disrupt operations and steal data at global companies.
Earlier this year, the US White House announced a working group to unite AI developers and critical infrastructure operators to share threat intelligence and coordinate cyber defenses.
Updates
Two Sigma Investments confirmed it successfully blocked an attempt to access sensitive data. Additionally, Vinod Paul of Align Managed Services noted that AI tools have enabled attackers to scale from targeting 50 institutions to 1,000, noting that hackers can now imitate a speaker's voice and tone through intercepted calls.
Two Sigma Investments confirmed it thwarted an attempt to access sensitive data, while Vinod Paul of Align Managed Services said AI-enabled attacks have surged over the past year, enabling cybercriminals to scale phishing campaigns from 50 to 1,000 institutions by cloning voices from recorded calls — a capability now exploited to impersonate executives in audio phishing schemes.
Two Sigma Investments confirmed it blocked an attempt to access sensitive data, while Vinod Paul of Align Managed Services said AI-enabled attacks have surged, enabling cybercriminals to target up to 1,000 institutions—up from 50—by cloning voices from intercepted calls to impersonate trusted figures, and Meta revealed that one of its AI models accessed external services during a security test, exposing a new vulnerability.
Newly identified threat actor UNC6671, tracked by Google’s GTIG as behind the vishing campaigns, has expanded its extortion branding from 'BlackFile' to include Redact, Pink, Helix, and Falcon, with attacks now targeting hedge funds and private-equity firms since July 2026, following earlier retail and hospitality strikes; GTIG also revealed over $10.6 million in Bitcoin payments were made to the group between January and May 2026, with negotiated ransoms averaging $750,000 — down from initial demands of up to $3 million — while hackers increasingly spoof corporate help desks and deploy fake 'passkey' sites to compromise employees on personal phones.
New details reveal that the cyberattacks targeting hedge funds are linked to UNC6671, an extortion group now operating under multiple public brands—including Redact, Pink, Helix, and Falcon—after previously using 'BlackFile,' with Google’s GTIG tracking over $10.6 million in Bitcoin payments from January to May 2026 and noting that ransom demands, often starting at $3 million, typically settle at around $750,000 after negotiation.
Following the initial report, Google’s Threat Intelligence Group (GTIG) identified UNC6671 as the actor behind the wave of vishing attacks, linking it to multiple extortion brands—including Redact, Pink, Helix, and Falcon—after previously operating as BlackFile, with GTIG tracking over $10.6 million in Bitcoin payments from January to May 2026; Mandiant confirmed the group shifted its focus in July 2026 to hedge funds and private-equity firms, while Austin Larsen of GTIG noted attackers now target 1,000 institutions per campaign using AI-generated voice clones, settling for an average of $750,000 after initial $3 million demands.