Detect Deepfakesby Resemble AI
Deepfake case study · Audio

AI Voice Phishing Fuels Wave of Cyberattacks on Wall…

Wall Street hedge funds including Point72 and Two Sigma have faced a surge of AI-driven voice phishing attacks aimed at extracting sensitive firm information

Incident date
Sep 2024
Target
Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel
Updated Aug 6, 2026 · 1 min read

Major Wall Street hedge funds and private equity firms have recently been targeted by a wave of sophisticated cyberattacks utilizing artificial intelligence to mimic voices. These voice phishing attempts represent a growing trend in the financial sector where AI tools are being used to lower the barrier for large-scale social engineering.

What happened

In early September 2024, multiple prominent investment firms were targeted by attackers using AI voice synthesis. Point72 Asset Management confirmed it was hit by a hacking attempt, though initial reviews indicated no client information was compromised. Similarly, Two Sigma Investments reported that its security team successfully blocked attempts to access sensitive data, confirming that no systems or information were affected. Other firms targeted in the campaign included Millennium Management and Citadel.

Security experts note that these attacks leverage AI to replicate a speaker's voice, tone, and mannerisms, allowing hackers to eavesdrop on calls or generate deceptive audio to extract information. While targeted attacks were historically limited in scope, the accessibility of modern AI systems now allows threat actors to scale operations from dozens of firms to thousands. Beyond remote phishing, similar techniques have been used to impersonate IT staff to gain physical entry to offices. The Financial Industry Regulatory Authority (FINRA) has since engaged with member firms to coordinate responses and share threat intelligence. Industry analysts warn that as AI makes these specialized skills more common, financial institutions must significantly improve security practices to counter the risk of large-scale data theft or ransom demands.

Sources