Point72 voice deepfake — Aug 2026
In August 2026, attackers used AI-powered voice cloning to impersonate executives at major Wall Street firms to attempt system access
- Incident date
- Aug 2026
- Target
- Point72, Citadel, Two Sigma, and Millennium Management
In August 2026, a wave of AI-powered voice phishing, or vishing, targeted several prominent financial institutions, including Point72, Citadel, Two Sigma, and Millennium Management. The attackers utilized synthetic voice technology to impersonate executives and trusted colleagues, aiming to trick employees and helpdesk staff into granting unauthorized system access or resetting credentials.
What happened
The attackers bypassed traditional software security by targeting human decision-making processes. By utilizing publicly available audio—such as earnings calls, interviews, podcasts, and webinars—the perpetrators created highly accurate voice clones of senior personnel. These synthetic voices were used to initiate fraudulent requests for sensitive information or access privileges.
Security teams at the targeted firms were able to detect the attempts before significant damage occurred. Two Sigma reported that its security team successfully blocked the attack with no impact on data or systems, while a preliminary review by Point72 found no evidence of client data theft. The incident highlights a shift in cybercrime where AI is used to automate and scale social engineering, moving the threat from manual, individual attempts to potentially industrial-scale operations. Experts suggest this attack demonstrates the inadequacy of relying on human intuition and voice recognition for identity verification, noting that organizations must move toward deterministic cryptographic proof to secure high-risk workflows against increasingly sophisticated deepfake threats.