344
Productivity & Workflow355
Automation & Workflow224
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps174
Writing & Content Creation203
Data & Analytics141
Photography & Imaging156
Design & Creative170
Customer Support131
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Point72, Citadel, and Millennium were targeted by phone-based phishing scams that tried to trick staff into giving away login details, the FT reports.
In short: Several large US hedge funds have recently been targeted by voice phishing cyber attacks, where scammers call employees and pretend to be trusted coworkers.
Point72, Citadel, and Millennium Management were among the hedge funds targeted in recent days, according to people familiar with the matter, as reported by the Financial Times. The attacks used audio “phishing,” meaning criminals try to talk someone into sharing private information over the phone.
At least some attackers posed as a firm’s internal help desk. That is like someone calling you and pretending to be your company’s IT support. The goal was to get employees to hand over login details, including information tied to “authenticator apps” (apps that generate a one-time code, like a second lock on a door after your password).
Point72 was investigating the incident to see if its systems were breached, meaning whether attackers got inside its network. The firm contacted law enforcement and hired cybersecurity experts, and it told investors it did not believe client information was stolen. People familiar with Citadel said it did not appear to have been breached, and noted that phishing attempts are common but have increased recently.
The Financial Times said it was not clear who was behind the attacks or whether they were coordinated. Bloomberg first reported the attempted attacks at some firms. Google’s cyber defense team also described similar phone-based scams hitting law firms and financial institutions in a June report.
Firms are likely to tighten internal security checks for phone requests, especially for password resets and account recovery. A key issue is that newer AI tools can make impersonation easier, including more convincing scripts and voice mimicry, which could increase this type of attack.
Source: Financial Times