AI Voice-Cloning Campaign Against Hedge Funds Signals…
Major hedge funds including Point72, Two Sigma, and Citadel were targeted by an AI voice-cloning campaign designed to manipulate IT help desks into…
- Incident date
- Aug 2026
- Target
- Point72, Two Sigma, and Citadel
In August 2026, a sophisticated AI-powered voice-cloning campaign targeted major hedge funds, including Point72, Two Sigma, and Citadel. These incidents highlight a critical shift in cybercrime where attackers exploit human-based identity verification processes rather than technical vulnerabilities.
What happened
The attackers utilized AI-generated voices to impersonate trusted executives during interactions with IT help desks. By leveraging seconds of publicly available audio—sourced from earnings calls, interviews, webinars, and podcasts—the attackers created convincing clones to manipulate staff into approving password resets, granting privileged access, or facilitating financial transactions. According to industry experts, these attacks expose a fundamental flaw in enterprise security: the reliance on human intuition and voice recognition to verify digital identities. As generative AI tools improve, the distinction between authentic and synthetic audio has become nearly impossible for human listeners to detect, rendering traditional awareness training and subjective judgment insufficient defenses. The incidents demonstrate that attackers are moving toward industrial-scale machine automation to bypass identity controls. Security professionals now argue that organizations must move away from human-dependent verification procedures. Instead, they recommend redesigning high-risk workflows to require phishing-resistant, device-bound authentication that relies on deterministic cryptographic proof rather than the recognition of a familiar voice. By removing human guesswork from critical security processes, firms can render AI impersonation attacks ineffective.