Detect Deepfakesby Resemble AI
Deepfake case study · Audio

Wall Street hit by wave of “vishing” hack attempts -…

Major global hedge funds including Point72 and Citadel faced a wave of AI-driven voice phishing attacks designed to gain unauthorized system access

Incident date
Aug 2026
Target
Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel
Updated Aug 7, 2026 · 1 min read

In August 2026, several of the world's largest hedge funds and asset managers were targeted by a coordinated campaign of AI-enabled voice phishing, or vishing. The attempted breaches hit notable firms including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel, as well as multiple private equity firms. While some firms reported that security teams successfully intercepted the attempts before data or systems were compromised, the incident has highlighted the increasing scalability of AI-driven social engineering.

What happened

The attackers utilized generative AI tools to clone the voices, tones, and speech patterns of real employees and executives. By impersonating colleagues over the phone, the fraudsters attempted to manipulate staff into granting unauthorized access to internal systems. Cybersecurity experts noted that this methodology represents a significant shift in threat intelligence, as generative AI allows attackers to scale operations that previously required manual effort, moving from targeting dozens of organizations to thousands at a low cost.

While the target list was not considered unique, the sophisticated use of voice synthesis to bypass standard verification protocols marked a significant escalation. The Financial Industry Regulatory Authority (FINRA) confirmed it has been in contact with member firms regarding these attempts. The incident has prompted broader industry concern, with JPMorgan Chase CEO Jamie Dimon spearheading an effort to expand the Alliance for Critical Infrastructure (ACI) to facilitate better information sharing regarding AI-driven threats. For the insurance industry, the incident has reignited debates regarding coverage gaps, as carriers and brokers assess whether standard cyber policies are sufficient to address losses stemming from AI-generated voice impersonation, or if standalone crime policies with specific social engineering extensions are necessary.

Sources