Visualização de leitura

Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaign

Point72

A cyberattack on Wall Street recently targeted several leading hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers used voice phishing, or "vishing," to trick employees into revealing sensitive information or granting access to internal systems.  Cybersecurity experts say such attempts are common because financial institutions store highly sensitive data. However, the latest incidents highlight how cybercriminals are increasingly combining traditional social engineering tactics with artificial intelligence to make impersonation attempts more convincing. 

Point72 Says No Client Data Was Compromised 

According to reports, Point72 Asset Management informed investors on August 5 that it had been targeted in the latest cyberattack on Wall Street. Bloomberg first reported the communication, citing a source familiar with the matter.  The firm said it was reviewing the incident and that no client information had been stolen. Point72 declined to comment publicly.  The campaign extended beyond Point72, with hackers also attempting to breach the information systems of Millennium Management, Two Sigma Investments, and Citadel, according to sources. 

Voice Phishing Remains an Effective Attack Method 

The attackers relied on voice phishing, a social engineering technique in which criminals impersonate trusted individuals—often IT support staff—to persuade employees to disclose confidential information or provide system access.  Cybersecurity experts told Reuters that these attacks are routine because of the valuable information held by financial firms. Rather than exploiting software vulnerabilities, voice phishing succeeds by manipulating human behaviour.  The tactic has also been used successfully by the cybercriminal group "Scattered Spider," a loosely organized network of young hackers that has targeted numerous companies in recent years. 

AI Is Increasing the Sophistication of Cyberattacks 

Security experts say the attempted cyberattack on Wall Street demonstrates how artificial intelligence is making social engineering campaigns more persuasive and difficult to detect.  A similar trend was highlighted in June, when Google's cybersecurity unit published a report detailing a campaign targeting U.S. law firms and other professional and financial services organizations.   According to the report, attackers posed as IT support personnel through voice phishing calls and, in some cases, even visited offices while pretending to be IT maintenance staff. 

Growing Cyber Risks for Financial Firms 

The attempted cyberattack on Wall Street comes as organizations worldwide face a rise in AI-powered cyberattacks and ransomware incidents that disrupt operations and steal sensitive data.  In response to the growing threat, the White House announced a working group earlier this year that brings together AI developers and critical infrastructure operators to share threat intelligence and strengthen cyber defenses.  Although Point72 said no customer information was compromised, the attempted attacks on several prominent hedge funds underscore the persistent cybersecurity risks facing the financial sector and the increasing use of AI-enhanced social engineering by threat actors. 

Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT

Minnesota Medicaid fraud

Four Minnesota men have pleaded guilty to a Minnesota Medicaid fraud scheme that allegedly stole approximately $2.2 million from the state’s Housing Stabilization Services (HSS) program and used artificial intelligence to fabricate records when insurance companies requested documentation. The defendants admitted to submitting thousands of claims for services they never provided or significantly inflating claims to obtain higher reimbursements. The case involves four Twin Cities-area men who operated Brilliant Minds Services LLC from the Griggs-Midway Building in St. Paul, Minnesota. According to court documents, the business enrolled as a Medicaid program provider and claimed to help people with disabilities, including seniors and individuals with mental illnesses and substance use disorders, find and maintain housing through the now-defunct HSS program.

Minnesota Medicaid Fraud Scheme Targeted 350 Recipients

According to prosecutors, Moktar Hassan Aden, 31, Mustafa Dayib Ali, 29, Khalid Ahmed Dayib, 26, and Abdifitah Mohamud Mohamed, 27, signed up approximately 350 people for HSS. The defendants then billed Medicaid for services they allegedly did not provide to those recipients. The scheme reportedly operated from April 2022 through April 2025. During that period, the four men allegedly submitted thousands of HSS claims and fraudulently obtained approximately $2.2 million from Minnesota Medicaid. The case highlights the alleged misuse of a government program designed to provide housing-related support to vulnerable people. Authorities said the defendants exploited the program by claiming reimbursements for services that were never delivered or by submitting inflated claims.

Artificial Intelligence Used to Fabricate Records

The case also highlights the use of artificial intelligence in an alleged effort to conceal healthcare fraud. When insurance companies requested supporting documentation for the claims, the defendants used ChatGPT to fabricate records, according to court documents. The use of ChatGPT to create fake documentation adds another dimension to the health care fraud case, as authorities continue to investigate alleged schemes involving government-funded programs. The defendants allegedly used the fabricated records to conceal the fraudulent claims and support services they had claimed to provide. Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division said the defendants exploited vulnerable people and a vulnerable program for financial gain. U.S. Attorney for the District of Minnesota Daniel N. Rosen said Medicaid fraud carries serious consequences and that the funds involved were intended to support vulnerable Minnesotans relying on housing and recovery services.

Four Defendants Plead Guilty to Wire Fraud

In separate hearings held between July 7 and July 23, 2026, all four defendants pleaded guilty to one count of wire fraud. Each faces a maximum penalty of 20 years in prison. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors. Sentencing dates have not yet been set. The FBI, the U.S. Internal Revenue Service, Criminal Investigation, and the U.S. Department of Health and Human Services, Office of Inspector General, are investigating the case. Trial Attorney Raymond E. Beckering III of the Criminal Division’s Fraud Section and Assistant U.S. Attorney Matthew Murphy for the District of Minnesota are prosecuting the case.

Health Care Fraud Strike Force Continues Investigations

The case is part of the ongoing collaboration between the U.S. Attorney’s Office for the District of Minnesota and the Health Care Fraud Strike Force to combat fraud targeting government programs. The Department of Justice’s Health Care Fraud Strike Force Program currently includes nine strike forces operating across federal districts. Since 2007, the program has charged more than 6,200 defendants who collectively billed federal health care programs and private insurers more than $45 billion. The case also comes as the Justice Department’s National Fraud Enforcement Division focuses on investigating and prosecuting fraud against the American people. Authorities said efforts to combat fraud remain part of broader work targeting fraud, waste, and abuse within federal benefit programs.

CERT-In Warns of AI-Driven Cyber Threat Surge, MSMEs at Highest Risk

CERT-In advisory

India’s cybersecurity watchdog, CERT-In, has raised concerns of the nature of modern cyber threats, particularly those driven by artificial intelligence. In its latest advisory, the cybersecurity watchdog has highlighted how frontier AI technologies are reshaping the threat landscape, making cyberattacks faster, more scalable, and far more accessible, even to less skilled attackers. The warning places a special emphasis on Micro, Small, and Medium Enterprises (MSMEs), which are becoming prime targets due to their comparatively weaker security frameworks.  According to CERT-In, the rise of AI-powered tools marks a significant turning point in how cyberattacks are conceived and executed. What once required advanced technical expertise and hours of manual effort can now be accomplished in a fraction of the time through automation. The cybersecurity watchdog noted that modern AI systems are capable of independently scanning large volumes of source code, identifying deeply embedded vulnerabilities, and even launching coordinated, multi-stage cyberattacks. This shift has introduced what the agency describes as an era of “automation and scale” in cybercrime. 

From Manual Intrusion to AI-led Cyberattacks 

CERT-In’s advisory explains that traditional hacking methods involve painstaking manual processes and highly specialized knowledge. Attackers would typically spend hours, if not days, probing systems for weaknesses before exploiting them. However, AI has fundamentally altered this dynamic. Frontier AI systems can now detect “zero-day” vulnerabilities, previously unknown flaws, in mere seconds.  More concerning is the ability of these systems to “chain” multiple vulnerabilities together. By linking weaknesses across different applications or platforms, attackers can orchestrate comprehensive attacks that compromise entire networks from end to end. This level of sophistication was once limited to highly skilled professionals or state-sponsored actors. Today, however, the cybersecurity watchdog warns that such capabilities are accessible, effectively lowering the barrier to entry for cybercriminals. 

MSMEs Under Heightened Risk 

The advisory stresses that MSMEs are particularly vulnerable in this new threat environment. Unlike large enterprises, MSMEs often operate with limited budgets and lack dedicated cybersecurity teams or advanced monitoring systems. This makes it easier for attackers to leverage AI-driven tools.  CERT-In has pointed out that because AI simplifies and automates many aspects of cyberattacks, even individuals with minimal technical expertise can now carry out highly precise and damaging operations. As a result, MSMEs face a disproportionate level of risk. A successful breach could lead to severe consequences, including data theft, operational disruptions, or ransomware attacks that many smaller businesses are ill-prepared to manage.  The cybersecurity watchdog has cautioned that without immediate and meaningful improvements in their security posture, MSMEs could suffer significant financial and reputational damage. The growing accessibility of AI-powered attack tools means that the threat is no longer hypothetical but immediate and widespread. 

Recommended Security Measures 

In response to these emerging risks, CERT-In has outlined several critical steps that organizations, especially MSMEs, should take to strengthen their defenses. One of the primary recommendations is the deployment of robust threat detection systems combined with continuous network monitoring. These measures can help identify unusual activity early and prevent attacks from escalating.  Another key focus area highlighted by the cybersecurity watchdog is patch management. As AI tools enable attackers to quickly identify and exploit unpatched vulnerabilities, delays in updating software can create significant security gaps. CERT-In stresses that the timely application of patches is essential to minimizing exposure.  Additionally, maintaining comprehensive system logs is strongly advised. Detailed logs play a crucial role in forensic investigations, helping organizations understand how an attack occurred and what vulnerabilities were exploited. This information is vital for preventing future incidents and strengthening overall cybersecurity resilience. 
❌