Cyber campaign targets hedge fund giants with voice phishing attacks



A coordinated cyber campaign targeting some of the world’s largest hedge funds has highlighted the growing threat posed by social engineering attacks, with Google researchers warning that financially motivated hackers are increasingly focusing on the alternative investment industry.

According to Google Threat Intelligence Group, the attacks have been attributed to UNC6671, an extortion group linked to the former BlackFile operation.

Rather than exploiting software vulnerabilities, the hackers reportedly used voice phishing, or “vishing”, impersonating internal IT support staff to persuade employees to reveal login credentials or approve access requests.

Human error remains the weakest link

Among the firms reportedly targeted were Point72 Asset Management, Millennium Management, Citadel and Two Sigma. Point72 told investors it had identified an attack but found no evidence that client data had been compromised, while Two Sigma said it had blocked an attempted intrusion before its systems were affected. Millennium and Citadel declined to comment.

Google says the group’s focus shifted during July from sectors such as manufacturing and hospitality towards hedge funds, private equity firms, law firms and financial ratings agencies, reflecting the increasing value of financial-sector data to cyber criminals. Reuters reported that dozens of investment firms and financial institutions were targeted, with attackers creating customised phishing websites and spoofing corporate help desks.

Voice comms ‘not enough’

As firms continue to invest heavily in cloud platforms, alternative data and AI tools, attackers are increasingly targeting employees rather than systems. The latest campaign suggests that staff training, identity verification and multi-factor authentication remain among the industry’s most important defences against operational risk.

“My advice for clients has been to ensure all employees understand that voice communications alone should no longer be treated as sufficient proof of identity and give them the confidence to question unusual requests coming via apps,” said Simon Eyre, chief information security officer at Drawbridge, a cybersecurity firm.

“Our Cyber Risk Intelligence helps firms identify gaps in their cybersecurity program and strengthen resilience in circumstances just like these.”