Recent reports that several of Wall Street’s largest hedge funds have been targeted by sophisticated cyber attacks serve as another reminder that cyber risk is no longer defined solely by technical vulnerabilities. Increasingly, attackers are exploiting people rather than systems.
According to reports, several prominent investment firms were subjected to voice phishing (‘vishing’) attempts, where criminals impersonated internal IT support teams in an effort to persuade employees to disclose authentication credentials. While there is currently no indication that all of the targeted firms suffered successful breaches, the incidents demonstrate how even organisations with significant cyber security investment remain attractive targets.
Why Financial Institutions Are Being Targeted
Investment managers, hedge funds and financial institutions hold exceptionally valuable information. Trading strategies, confidential client data, proprietary algorithms and significant financial assets make these organisations prime targets for organised cyber criminals and, potentially, state-sponsored threat actors.
Unlike traditional phishing emails, voice phishing relies on social engineering. Attackers use convincing telephone calls, often supported by publicly available information and increasingly sophisticated AI-generated voices, to build trust and persuade employees to bypass established security procedures.
This type of attack can be particularly effective because it exploits human judgement rather than technical weaknesses.
AI Is Changing the Threat Landscape
Artificial intelligence is making cyber attacks more convincing, more scalable and more difficult to detect.
Criminals can now generate highly realistic voices, personalise attacks using publicly available information and automate large volumes of social engineering attempts. As these capabilities become more accessible, organisations should expect increasingly sophisticated attacks against employees at every level.
The question is no longer whether businesses will experience attempted cyber attacks, but whether their controls are sufficient to prevent a successful compromise.
Cyber Security Requires More Than Technology
Technology remains an essential part of cyber defence, but it cannot eliminate the human element.
Businesses should ensure employees understand that legitimate IT teams should never request authentication codes, passwords or multi-factor authentication approvals over the telephone. Verification procedures should be clearly documented, regularly tested and consistently followed.
Organisations should also consider:
· Regular phishing and voice phishing awareness exercises.
· Robust identity verification procedures for IT support requests.
· Multi-factor authentication with secure enrolment processes.
· Continuous monitoring for unusual account activity.
· Incident response plans that include social engineering scenarios.
The Insurance Perspective
Many organisations assume cyber insurance only responds following a ransomware attack or major data breach. In reality, a well-structured cyber insurance programme can provide much broader protection.
Depending on policy wording, cover may include:
· Incident response and forensic investigation.
· Legal and regulatory support.
· Data recovery and system restoration.
· Business interruption losses.
· Notification and credit monitoring costs.
· Cyber extortion.
· Third-party liability arising from data breaches.
· Access to specialist cyber response providers.
However, policy wording, security requirements and insurer expectations continue to evolve as the threat landscape develops. Businesses should regularly review whether their insurance programme remains aligned with their cyber exposure and operational risk.
A Reminder for Every Business
Although these latest incidents involve some of the world’s largest hedge funds, the underlying lesson applies across every sector.
Cyber criminals increasingly target people instead of technology because human trust is often easier to exploit than sophisticated security systems. As AI continues to improve the effectiveness of social engineering attacks, organisations should ensure that cyber resilience extends beyond firewalls and software to include governance, employee awareness and appropriate insurance protection.
Cyber security should be viewed as a combination of people, processes, technology and insurance. Weakness in any one of those areas can create opportunities for attackers, regardless of the size or sophistication of the organisation.
To discuss your cyber risk exposure or review your existing cyber insurance programme with a broker, contact Daniel Moss at Daniel.moss@Wdenis.co.uk or on 0044 (0) 113 2439812.
Specialist contact
Mark Dutton
Chief Commercial Officer
T. +44 (0) 7831 366 469
E. mark.dutton@wdenis.co.uk
Arrange a call back


