Major asset management firms on Wall Street, including leading hedge funds such as Two Sigma Investments, Citadel, and Point72 Asset Management, have recently been targeted by a wave of sophisticated cyberattacks. These attacks also extended to several private equity firms, attempting to infiltrate their information systems. The incidents highlight the increasing cybersecurity risks faced by financial institutions, particularly as they rely more heavily on complex information systems, algorithmic trading, and cloud infrastructure, making them prime targets for cyber criminals.

The specific methods used by the attackers, their identities, and whether any sensitive data has been compromised remain unclear. These recent events have intensified market concerns regarding the vulnerability of financial institutions to cyber threats. The financial industry, due to its critical role and vast financial reserves, is a persistent target for malicious actors, with the finance and insurance sectors accounting for 27% of all cyber incidents in 2025, according to IBM’s X-Force 2026 Threat Intelligence Index.

Approximately half of investment firms, including hedge funds, reported experiencing a data breach in the past 12 months. Phishing was identified as the top concern by about two-thirds of surveyed firms. Furthermore, around half of the reported incidents were linked to third-party risks. In response, 8 out of 10 hedge funds increased their cybersecurity spending in 2025, with plans for further increases over the next 12 to 24 months to enhance resilience in areas like incident response, threat detection, cloud security, endpoint security, and identity and access management.