A coordinated wave of AI-powered voice phishing has targeted some of Wall Street's largest hedge funds, exposing how voice-cloning tools have lowered the cost of attacking financial firms.
AI voice-cloning tools let attackers impersonate executives at hedge funds including Two Sigma, Citadel and Point72 — which together manage more than $150 billion — in a coordinated vishing campaign that also hit several private equity firms.
"Before they could attack 50 entities in a targeted attack, now they can do 1,000," Vinod Paul, president of Align Managed Services, which specializes in hedge fund cybersecurity, said.
Two Sigma, which oversees $75 billion, said its security team blocked the attempt and found no impact on data or systems. Point72 told investors it was attacked, with no initial indication client information was stolen. Spokespeople for Citadel and Millennium Management declined to comment on whether systems were breached.
The campaign marks an escalation in AI-enabled fraud that is pushing financial firms to raise cybersecurity budgets, a tailwind for security vendors such as CrowdStrike, Palo Alto Networks and Fortinet as they compete for a growing share of institutional spending.
The technique, known as vishing, relies on technology that listens to phone calls and replicates a speaker's voice, tone and phrasing to fabricate convincing fake calls. Employees are manipulated into surrendering credentials or granting system access. The approach resembles tactics used by Scattered Spider, the group behind 2023 ransomware attacks on Caesars Entertainment and MGM Resorts, though no attribution has been made in the current campaign.
AI Commoditizes Hacking Skills
Will Wilson, chief executive of Antithesis, a software firm backed by Jane Street, said AI has restructured cyberattacks. "The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale," Wilson said. "Everybody will have to seriously level up. Otherwise they are going to be in big trouble."
The attacks follow a similar vishing wave that Google's cybersecurity unit flagged in June targeting law firms and professional services companies, in some cases with attackers physically entering offices posing as IT workers. The pattern shows the threat spreading from professional services into financial institutions.
Regulators and Spending Respond
FINRA, which oversees brokers and securities professionals, has been in contact with member firms about the attempted breaches. The regulator launched its Financial Intelligence Fusion Center in March, a secure portal for sharing fraud threat intelligence and coordinating responses. The White House earlier this year announced a working group uniting AI developers and critical infrastructure operators to share threat intelligence.
The incidents add to a string of breaches hitting wealth management firms this year. Mega-RIA Mariner disclosed a cloud breach affecting nearly 9,000 individuals, and Mercer faces class action litigation after a breach linked to the ShinyHunters group. Hightower Advisors, Edelman Financial Engines, Beacon Pointe, Betterment and Ameriprise were also targeted.
For investors, the campaign signals sustained demand for AI-security tools. CrowdStrike, Palo Alto Networks and Fortinet are positioned to capture rising institutional spending as financial firms upgrade defenses against deepfake and voice-cloned communications. Firms that fail to update security infrastructure face reputational damage and regulatory scrutiny, raising the operational risk embedded in financial services stocks.
This article is for informational purposes only and does not constitute investment advice.