Detect Deepfakesby Resemble AI
Deepfake case study · Audio

Breaking down the Wall Street vishing wave: how AI voice…

In August 2026, major hedge funds including Point72 and Citadel were targeted by a wave of AI-powered voice phishing attacks using cloned executive voices

Incident date
Aug 2026
Target
Point72, Citadel, Millennium Management, and Two Sigma
Updated Aug 7, 2026 · 1 min read

In early August 2026, a coordinated wave of AI-powered voice phishing, or vishing, targeted several major Wall Street hedge funds, including Point72, Citadel, Millennium Management, and Two Sigma. While the campaign was widespread, targeting these firms along with various private equity companies, the attacks largely failed to result in successful breaches. The incident highlights an emerging trend where generative AI is used to scale social engineering efforts against high-value financial targets.

What happened

Attackers impersonated trusted colleagues or senior executives by using AI to clone specific voices, drawing from public audio sources such as earnings calls, podcasts, and conference recordings. The impersonators captured the target’s voice, cadence, and phrasing to create a sense of legitimacy during phone calls. The primary objective of these calls was to gain unauthorized access by tricking employees into reading back one-time passcodes, approving multi-factor authentication (MFA) prompts, resetting credentials, or installing remote support tools.

Two Sigma, which manages approximately $75 billion in assets, confirmed that its security team intercepted the attempt before any data or systems were impacted. Point72 informed investors that while the firm was targeted, an initial review indicated no client data had been compromised, with a full assessment still underway. Other firms, including Citadel and Millennium Management, declined to comment on the record.

Industry regulators have responded to the wave, with FINRA confirming contact with member firms regarding these attempts. The regulator utilized its Financial Intelligence Fusion Center, a secure channel launched in March 2026, to facilitate cross-firm threat sharing. While some experts noted that the phone-call tactics are reminiscent of those associated with the group Scattered Spider, no specific actor has been publicly confirmed as responsible for this campaign.

Sources