- Cybersecurity Docket
- Posts
- Point72, Citadel Among Hedge Funds Hit by AI Vishing Attacks
Point72, Citadel Among Hedge Funds Hit by AI Vishing Attacks
Plus, yet another AI model escaped its testing environment.

Good morning! Here’s what’s up.

People
Shane Marshall has joined Sidley Austin as chief information officer (CIO). Marshall joins the law firm after more than 19 years with Accenture, where he most recently served as global lead of enterprise platforms.
Reed Rayman has been appointed as head of the AI Sector for Apollo, overseeing the firm’s global coverage of the AI and digital infrastructure ecosystem as part of a cross-firm effort to bring Apollo’s full range of capital solutions to leading technology companies. Rayman, who has been with Apollo since 2010, most recently served as deputy co-head of Apollo’s Hybrid business.

Clips ✂️
Point72, Citadel among hedge funds hit by AI vishing attacks
Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel were all targeted in a coordinated wave of cyberattacks in recent days, with attackers using AI-powered voice phishing to attempt to extract sensitive data from employees of the Wall Street money managers.
According to a Bloomberg report on Wednesday, Point72 informed investors it had been attacked, though the firm's initial review found no client information was stolen. The firm told investors it was still reviewing the incident. Spokespeople for Millennium, Point72, and Citadel declined to comment to Bloomberg. Two Sigma, which manages $75 billion in assets, told Bloomberg it successfully blocked the attempt. The voice fraud is known as "vishing" in cybersecurity terms.
"Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems," a Two Sigma spokesperson said in a statement. "We continue to monitor the situation closely."
Chinese startup Moonshot's AI model breaks out of testing environment, researchers say
Chinese startup Moonshot's flagship AI model, Kimi K3, escaped a cybersecurity testing environment developed by the UK AI Safety Institute, research firm Frontier Security said on Thursday, raising concerns over the cybersecurity risks posed by advanced AI systems.
AI models are typically run in isolated "sandboxes" during cybersecurity tests to block access to external information and assess their ability to solve problems independently.
Kimi K3 bypassed one such sandbox, allowing it to access information beyond the test environment, U.S.-based cybersecurity research firm Frontier Security said.
The researchers warned that if one "high-reasoning model" discovers such a shortcut, other models with similar access could likely do the same.
…
Kimi K3's cybersecurity evasion follows a string of similar incidents recently reported by companies such as Meta, OpenAI, and Anthropic.
Who is liable when AI goes rogue? Lawyers see new risks
Major artificial intelligence developers have reported cases of their autonomous AI models breaching other companies' cyber infrastructure, raising questions about who may be held legally responsible when AI systems act without direct human oversight.
Here's a look at some of the legal questions surrounding autonomous AI breaches.
…
WHO COULD SUE?
Plaintiffs could include companies whose cyber defenses were breached as well as those companies' workers or employees. Customers of a company that was breached could attempt to sue if their individual data was exposed. Shareholders could also potentially bring claims if a cybersecurity breach led to a drop in a company's value.
EXCLUSIVE: Hackers targeted US private equity, other firms including Blackstone, CME, data shows
Ransom-seeking hackers who use phone calls to compromise their victims targeted dozens of prominent U.S. financial institutions and other businesses over the past month, according to Google and internet intelligence data reviewed by Reuters.
The data shows the hackers devised websites aimed at stealing passwords from employees of private equity firms and financial companies including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's, as well as other businesses.
Google said in a blog post about the hacking campaign published on Thursday that the hackers operate under a range of names, including Redact, Pink, Falcon and Helix. … Its blog said in some cases companies, which it did not name, paid ransoms to the hackers.
Levi Strauss reports cybersecurity incident, says no consumer data affected
Levi Strauss & Co. reported Friday that it recently experienced a cybersecurity incident involving unauthorized access to company files. According to a press release statement based on a filing with the Securities and Exchange Commission, the breach was carried out through social engineering techniques that allowed an unauthorized third party to access three employees’ company-issued computers.
The company stated that, upon detecting the incident, it initiated response protocols, implemented containment measures, and engaged third-party cybersecurity experts. An investigation into the matter is ongoing.
…
Levi Strauss said preliminary findings indicate that certain corporate information was accessed and exfiltrated as a result of the breach. The company reported that its response efforts have successfully contained and terminated the unauthorized access. As of the time of the filing, Levi Strauss said no consumer data was impacted and there has been no interruption to business operations.
This week, the White House announced a new framework for regulating A.I. models, but it isn’t letting the public read it. We break down what we know about the rules and what the implications are for the industry and A.I. safety as a whole.
Then, yet another report details new incidents in which A.I. agents have gone rogue. Chris Painter, the president of METR, an independent A.I. evaluation organization, joins to discuss how we get these models under control.
And finally, we’re hopping on the Hot Mess Express for the very last time. We’ll rate the craziest tech headlines from the week, including Google’s announcement that Demis Hassabis is stepping into a new role.
👉This podcast by The New York Times is definitely worth a listen for those interested in a deeper dive conversation beyond this week’s cyber headlines.
