Bloomberg reported that several large asset management firms on Wall Street, including major hedge funds such as Two Sigma Investments, Citadel, and Point72 Asset Management, along with private equity firms, have been subjected to a series of complex cyberattacks. The attackers reportedly attempted to infiltrate the companies' information systems. The exact methods used, the identity of the attackers, and whether any sensitive data was compromised are currently unknown.
This incident highlights a growing concern regarding cybersecurity in the financial industry. Financial institutions, due to their significant financial reserves and extensive customer data, are attractive targets for cybercriminals. The finance and insurance sectors accounted for 27% of all cybersecurity incidents in 2025, making it the second-highest share across all industries, according to IBM’s X-Force 2026 Threat Intelligence Index. Ransomware attacks in the finance industry surged by 64% in 2023, nearly doubling the 2021 level.
Experts also note that new technologies, particularly generative AI, are increasing the speed and sophistication of cyberattacks. Kroll research indicates that 76% of organizations have experienced a security incident involving AI applications or models in the past two years. Regulators are advising a focus on resilience, emphasizing quick system restoration in the event of an attack. Phishing remains a top concern for about two-thirds of hedge funds, and about half of reported incidents were linked to third-party risks.
The broader financial system faces significant vulnerability, with a potential major cyberattack on a global payments system costing the world economy $3.5 trillion, as warned by Lloyd’s of London. A Bank of England survey of UK market participants now considers cyberattack risk to be the number one systemic risk. The 2023 ransomware attack on the New York arm of China’s largest bank, ICBC, disrupted the $25 trillion US Treasury bond market, exposing the fragility of interconnected financial systems and lack of sophisticated contingency planning.