A coordinated wave of AI-powered voice-cloning attacks has put some of Wall Street's largest money managers on high alert.
A coordinated wave of AI-powered voice-cloning attacks has put some of Wall Street's largest money managers on high alert.

AI-powered voice-cloning attacks targeted the information systems of at least three of the world's largest hedge funds in recent days, exploiting voice phishing to impersonate executives and seek access to internal networks.
Two Sigma Investments, a $75 billion asset manager, confirmed it repelled the attempt, with a spokesperson saying its security team responded quickly to a vishing campaign targeting the firm and others, with "no indication of any impact to our data or our systems."
The attackers also sought to breach systems at Citadel and Point72 Asset Management, as well as several private equity firms, according to people familiar with the matter. Spokespeople for Citadel and Point72 declined to comment. The campaign relied on AI and sound technology to replicate the exact voices, tones, and phrasing of legitimate executives, manipulating employees into surrendering sensitive information or granting network access.
The assault mirrors a broader surge in cyber threats hitting professional services over the past year. With Citadel managing $71 billion and Two Sigma $75 billion, a successful intrusion could shake investor confidence in institutional security and invite tighter regulatory oversight of financial firms' cyber defenses.
The technique marks an escalation in social-engineering attacks, moving beyond email phishing to real-time voice impersonation that is harder for employees to detect. Cybersecurity vendors including Palo Alto Networks, CrowdStrike, and Fortinet have flagged a rise in AI-enabled fraud as voice-cloning tools become cheaper and more accurate. Because vishing exploits human trust rather than software vulnerabilities, traditional perimeter defenses offer limited protection, pushing firms toward biometric verification, call-back protocols, and employee training.
The timing is awkward for the targeted managers. Citadel's flagship Wellington fund returned 5.9 percent in July, bringing its year-to-date gain to 12 percent, while Point72 fell 3.3 percent last month and Millennium lost 2.1 percent. A security lapse at any of these firms could compound reputational risk at a moment when performance is under scrutiny.
The wave of attacks comes as multistrategy funds, which manage hundreds of billions of dollars collectively, face intensifying scrutiny over their operational resilience. The firms targeted sit among the most prominent names in the industry, making them high-value targets for criminals seeking to exploit their scale and the volume of sensitive data they handle daily.
For investors, the episode is a reminder that the industry's largest allocators are now prime targets for AI-enabled fraud. Cybersecurity spending across financial services is expected to keep climbing as firms harden their defenses, a tailwind for vendors such as CrowdStrike and Palo Alto Networks. But the immediate risk is operational: a breach that compromises trading systems or client data could trigger outflows and regulatory penalties, a scenario no fund manager can afford as third-quarter performance gets underway.
The attack also highlights how quickly AI tools have lowered the barrier to sophisticated fraud. Voice-cloning software that once required studio-grade audio can now replicate a person's voice from a few seconds of recorded speech, a capability that has spread across consumer apps and dark-web marketplaces. For asset managers, whose employees routinely field calls from counterparties, brokers, and clients, the threat model has shifted from phishing emails to convincing audio that is difficult to distinguish from a genuine colleague.
Regulators have taken notice. Financial watchdogs in the US and Europe have stepped up guidance on AI-enabled fraud, urging firms to verify high-value transactions through multiple channels and to treat unsolicited voice requests with the same suspicion as email attachments. The wave of attacks on marquee hedge funds is likely to accelerate those efforts, adding compliance costs to an industry already managing rising operational expenses.
This article is for informational purposes only and does not constitute investment advice.