Vishing With Cloned Voices Hits Citadel, Point72, Two…
In August 2026 a coordinated voice phishing campaign targeted major Wall Street firms including Citadel and Point72 to harvest credentials via AI-cloned…
- Incident date
- Aug 2026
- Target
- Citadel, Point72 Asset Management, Two Sigma Investments, Millennium Management
In early August 2026, several prominent Wall Street financial institutions, including Citadel, Point72 Asset Management, Two Sigma Investments, and Millennium Management, were targeted by a coordinated voice phishing campaign. Unlike previous scams focused on wire transfers, this operation sought to harvest credentials, second-factor codes, and internal system access by impersonating known colleagues through real-time voice cloning technology.
What happened
The attack utilized real-time speech-to-speech voice cloning to mimic the voices of trusted individuals, enabling attackers to interact naturally with employees. The campaign was notable for its simultaneity, targeting multiple competing firms at once, which suggested a highly organized effort rather than an isolated incident. The primary goal was to manipulate help desk and IT support staff into resetting passwords or re-enrolling multi-factor authentication (MFA) tokens. By gaining these credentials, the attackers aimed to secure persistent access to internal infrastructure, which poses a significantly higher risk than one-time wire fraud.
While Two Sigma reported that their security team successfully responded to the attempt with no evidence of system impact, and Point72 confirmed no exfiltration of client information, others like Citadel and Millennium declined to comment. The US financial regulatory authority, FINRA, utilized this incident as the first real-world test for its Financial Intelligence Fusion Center. This campaign highlights a critical shift in the threat landscape: attackers are no longer exploiting technical software vulnerabilities but are instead weaponizing the inherent trust in voice communication to bypass standard verification processes. The incident serves as a stark reminder that voice should no longer be treated as a reliable authentication factor, as the ease of generating realistic clones using publicly available audio from podcasts and interviews has rendered traditional verification methods insufficient.