Wall Street Cyberattacks and Social Engineering

Cybersecurity is often imagined as a battle between hackers and technology. Businesses picture attackers breaking through security with 5 computer screens in an abandoned building. Those threats are real, but some of the most dangerous cyberattacks still begin in a much simpler way. . . A phone call. 

Recent reporting from Reuters revealed that hackers attempted a series of sophisticated cyberattacks against major Wall Street financial services firms and money managers. According to the report, some of the world’s largest hedge funds and private equity firms were targeted. The attacks allegedly involved cybercriminals calling employees and attempting to trick them into granting access or providing sensitive information and that should get every business leader’s attention. These attacks were not only about technology. They were about trust, pressure, persuasion, and human behavior. Even the most advanced financial organizations in the world can be targeted through social engineering. If firms with massive resources and mature security teams are facing this kind of threat, small and mid-sized businesses should not assume they are immune. The lesson is clear: cybersecurity is not just about protecting systems. It is about protecting people, processes, and access.

The Human Element Remains a Primary Attack Surface

Social engineering is the practice of manipulating people into taking actions that benefit an attacker. Instead of breaking into a system directly, attackers convince someone inside the organization to open the door for them. That may mean persuading an employee to share login credentials, approve a multi-factor authentication request, reset a password, install remote access software, download a file, disclose internal information, change payment details, or grant access to a system. Phone-based social engineering is especially dangerous because it feels personal and immediate. An attacker can pretend to be from IT, a vendor, a senior executive, a help desk provider, a software company, a bank, a client, or another trusted source. They can use urgency, confidence, technical language, and pressure to make the request feel legitimate. They may believe they are helping solve a problem, and that is what makes social engineering so effective.

Phone-Based Attacks Still Work

Many businesses have invested heavily in email security, spam filtering, endpoint protection, and cloud security tools. Those investments matter. But attackers are adaptable. If email filtering improves, they may shift to phone calls, text messages, messaging apps, fake help desk portals, or impersonation through collaboration tools. Phone-based attacks still work because they exploit real workplace behavior. Employees answer calls. IT teams troubleshoot access issues. Finance teams process urgent requests. Executives delegate. Vendors ask for updates. Help desks verify users. Remote employees rely on support. In that normal flow of business, a skilled attacker can blend in.

The danger increases when employees do not have clear procedures for verifying unusual requests. If someone calls claiming to be from IT and asks for a login code, does the employee know what to do? If a caller claims to be a vendor and asks for access, is there a formal verification process? If a person asks an employee to approve an MFA prompt, does the employee know that this could be an attack? Security awareness must move beyond email phishing. Employees need to understand that cyberattacks can come through the phone.

Scattered Spider and the Rise of Help Desk Manipulation

The Reuters article noted that phone-call tactics have been used successfully by cybercriminal groups such as Scattered Spider. This group has become known for social engineering, impersonation, and help desk-style attacks that target employees and IT support processes. These attacks often focus on identity. If an attacker can convince a help desk or employee that they are a legitimate user, they may be able to reset passwords, enroll new devices, bypass safeguards, or gain access to business systems.

This is why organizations must secure their support processes. Businesses need stronger verification methods for password resets, MFA changes, device enrollment, remote access support, and privileged account recovery. An organization can have strong technology but still be vulnerable if its support process can be manipulated.

AI Is Making Social Engineering More Dangerous

The Reuters article also referenced a broader surge in AI-powered cyberattacks and ransomware. This is a critical point because artificial intelligence is making social engineering more convincing and scalable. Attackers can use AI to research targets, write polished messages, imitate professional communication styles, generate scripts for phone calls, create realistic phishing emails, translate scams into fluent language, summarize public information about employees, and personalize attacks at scale. This does not mean every business should panic. It does mean every business should modernize its employee training and verification procedures. The old advice of “look for bad grammar” is no longer enough.

Some businesses may read about attacks on Wall Street and assume the threat does not apply to them. That would be a mistake. The same tactics used against major financial firms can be adapted to target small and mid-sized businesses. In fact, smaller organizations may be easier targets because they often have fewer security controls, less formal training, less mature access management, and more informal communication processes. A small business may not have billion-dollar assets, but it may still have bank accounts, payroll systems, customer data, employee records, vendor payments, contracts, cloud accounts, website access, and sensitive email communications. For an attacker, that is enough.

Verification Procedures Are a Business Control

One of the best defenses against phone-based social engineering is a clear verification process. Employees should not have to guess whether a request is legitimate. The business should define how sensitive requests are confirmed. If someone requests a password reset, there should be a secure verification process. If someone asks for payment changes, there should be a second approval step. If someone claims to be from IT, employees should know how to verify that request through an official channel. If a vendor asks for access, the request should be confirmed through known contacts, not through the phone number or email provided by the caller. Verification should be treated as a normal business practice, not as distrust. A strong culture makes it acceptable to pause, verify, and escalate. Employees should never feel pressured to bypass security for the sake of speed. The attempted attacks on major Wall Street firms show that cybercriminals continue to target the human layer of cybersecurity. Technology matters, but attackers know that people, processes, and trust relationships can be easier to exploit than systems.

Cybersecurity must be practical. It must prepare employees for real situations, not just theoretical risks.

Final Thoughts

The Wall Street cyberattack attempts are a reminder that social engineering remains one of the most effective tools in the cybercriminal playbook. Attackers do not always need to defeat technology. Sometimes they only need to convince one person to trust the wrong request. As AI makes scams more convincing and attackers continue to refine phone-based tactics, businesses must strengthen both technical controls and human readiness. The best defense is not fear. It is preparation. Businesses that train employees, enforce strong authentication, verify sensitive requests, monitor access, and build response plans will be far better positioned to withstand modern cyber threats.

Work With Cryptek

Cryptek provides cybersecurity assessments, vulnerability scanning, penetration testing, compliance risk assessments, threat prevention, and strategic cybersecurity guidance for businesses across Milwaukee and beyond. If your organization wants to strengthen employee awareness, reduce social engineering risk, review access controls, or prepare for today’s AI-powered cyber threats, Cryptek is ready to help. Contact Cryptek today to schedule a cybersecurity consultation and take the next step toward stronger protection.

Start working with our cybersecurity experts.