Major Wall Street firms targeted in wave of cyberattack attempts 

Hackers have launched a series of sophisticated cyberattack attempts targeting major Wall Street financial firms, including Point72 Asset Management, Citadel, Millennium Management and Two Sigma Investments with attackers attempting to gain access to internal information systems through voice phishing (vishing) and other social engineering techniques, according to Bloomberg.

Point72 notified investors that it was investigating the incident but said there were no initial indications that client information had been compromised.

   “Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a Two Sigma spokesperson said in a statement.

The Financial Industry Regulatory Authority (FINRA) has contacted member firms regarding the recent attempted cyberattacks. Earlier this year, FINRA launched its Financial Intelligence Fusion Center, a secure platform for sharing cyber threat intelligence and coordinating responses to increasingly sophisticated cyber and fraud threats targeting financial services firms.

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

“These attacks demonstrate that social engineering remains one of the most effective ways to bypass technical security controls. As attackers increasingly leverage AI and publicly available information to make vishing campaigns more convincing, organizations must strengthen identity verification processes and ensure employees are trained to verify requests rather than simply trust a familiar voice. The firms’ rapid detection also shows why layered defenses and intelligence sharing are critical for stopping these campaigns before they become breaches.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:

“Modern phishing campaigns often start with publicly available information and can be combined with previous data exposures to build a targeted profile on potential victims. AI can analyze massive amounts of data quickly to build profiles that would take a skilled human days or weeks. AI has lowered the barrier for cybercrime. What once required years of experience can now be done with very little effort or technical knowledge. Humans are the weakest link in both data incidents and social engineering and as voice impersonation become more convincing, we will reach a point where we cannot trust what we hear or what we see.

   “Cybersecurity is no longer only about protecting networks and endpoints. It’s increasingly about protecting decision making and the primary defense starts with education and changing the culture of data protection. AI powered social engineering is designed to manipulate human judgment, and organizations must recognize that their workforce is now a primary attack surface. When the goal of cyber criminals if financial gain it is only logical that investment firms that manage sensitive financial information are attractive targets.”

You have to assume that you’re a target. Thus you need your defences are set up to repel that threat. Otherwise, you need to assume that you are going to get pwned. It is that simple.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading