AI Voice Phishing Just Hit Wall Street's Biggest Names. Your Team Is Next.
- Morgan Ellis

- 27 minutes ago
- 6 min read

In the first week of August, hackers ran a coordinated wave of attacks against some of the best-resourced financial institutions in the world. According to Bloomberg's reporting, Point72 Asset Management confirmed it was attacked, with early indications that no client information was stolen. Attackers also went after Millennium Management, Two Sigma, Citadel, and several private equity firms in the same assault.
Two Sigma has a different story. Its security team detected and blocked the attempt outright, with no evidence any unauthorized access occurred.
Same attack. Same week. Two very different outcomes. That gap is the whole story, and it has nothing to do with which fund had a bigger security budget.
What actually happened
The method here wasn't a phishing email or a malware attachment. It was vishing, voice phishing, where attackers use technology to mimic a real person's voice, tone, and phrasing in a phone call to convince an employee to hand over access. Vinod Paul, president of Align Managed Services, told Bloomberg the economics behind this have changed. Attackers who once needed to hand-pick 50 targets for a serious campaign can now run the same operation against a thousand, because AI tooling makes the reconnaissance and voice cloning cheap.
This wasn't an isolated Wall Street incident either. InvestmentNews reported that FINRA has been in direct contact with member firms, activating its Financial Intelligence Fusion Center, a threat-sharing portal the regulator only stood up in March, for the first real test of its usefulness.
This has a name, and it's been active for months AI Voice Phishing
The hedge fund attacks didn't come out of nowhere. In June, Google's Mandiant division published a detailed report attributing a nearly identical campaign to a threat cluster tracked as UNC3753, also known as Luna Moth, Chatty Spider, or Silent Ransom Group. Between January and May, Mandiant found this group had already hit dozens of US law firms, professional services firms, and financial companies using the same playbook.
The attack chain is almost boringly simple, which is exactly why it works. It typically opens with an unremarkable invoice-themed email sent from a personal-looking address, no malicious link, no attachment, just a pretext. That email sets up a follow-up phone call. The caller poses as IT support, walks the employee through installing a remote access tool, and within hours, sometimes under an hour according to Mandiant's incident data, the attacker has staged and exfiltrated sensitive files.
Then comes the extortion. Mandiant documented cases where victims received an aggressive ransom demand within 30 minutes of the theft, giving them three days to pay before the attackers threatened to notify clients, partners, and employees directly and publish the stolen data.
In the most aggressive cases, when the phone call alone didn't work, the group sent someone to the target's office in person, posing as an IT technician who needed to "image the device" or run a local backup, then plugged in a USB drive.
Read that again. A person walked into a real office, claimed to be IT, and nobody stopped them.

Why this works on smart people at well-funded firms
None of the firms targeted this week are careless. Citadel and Point72 run some of the most sophisticated security operations in finance. The reason this campaign still lands is that it doesn't attack the network. It attacks the one thing every organization has to trust to function at all: the assumption that when someone calls claiming to be IT, support, or a colleague, they probably are.
AI has quietly removed the friction that used to make that kind of impersonation hard. Cloning a voice used to take real effort and real audio samples. Now it takes a few seconds of publicly available video and off-the-shelf tools. The FBI noted in a May advisory that this same group has posed as IT department employees since spring 2026, and has specifically targeted law firms since 2023, well before the AI tooling made it easy to scale.
What Two Sigma did differently
Public reporting doesn't give a full breakdown of Two Sigma's internal controls, but the pattern that stops this style of attack is well understood at this point, because Mandiant has now watched dozens of these incidents unfold. The firms that catch it share a few things in common:
A verified callback process for anything involving system access. If "IT" calls asking you to install something or grant access, you hang up and call the number in the internal directory, not a number the caller gives you.
A standing rule that no one requests credentials, screen-sharing, or remote access tools over an unscheduled call. Ever. No exceptions for urgency.
MFA that can't be talked around. Push-based or hardware-key MFA on every entry point, not just a code an employee might read aloud under social pressure.
A no-blame reporting culture. The employee who almost fell for it needs to feel safe flagging it immediately, not embarrassed into staying quiet.
None of this requires a nine-figure security budget. It requires a policy that's actually been said out loud, practiced, and reinforced until it's reflex.
What to do this week
If you run a business, especially one that handles client data, financial information, or protected health information, this is the week to act, not the week after the next headline.
Tell your team this happened. Not as a scare tactic, as a specific, current example. "IT support" calling out of nowhere, asking to install something, is exactly what hit Citadel's peers this week.
Confirm your callback verification policy exists and is written down. If it lives only in someone's head, it doesn't exist under pressure.
Check who can install remote access software on your systems. RMM tool abuse is central to this campaign. If any employee can install one without approval, that's your gap.
Ask your IT provider directly: would we have caught this? If the honest answer is uncertain, that uncertainty is the actual finding.
Where this becomes operational
This is the kind of threat that punishes reactive security and rewards governed, human-aware security. AI didn't create social engineering. It made it fast, cheap, and personalized enough to fool people who would have caught a clumsier attempt five years ago.
At Chibitek, this is the exact gap we close for clients: not just technical controls, but the verification habits, escalation paths, and staff training that make an attack like this a non-event instead of a headline. If you want a straight answer on whether your team would catch this, reach out. No pitch, no deck. Just a real assessment of where you stand.
Frequently asked questions
What is vishing?
Vishing, short for voice phishing, is a social engineering attack where criminals use phone calls, often enhanced with AI voice-cloning technology, to impersonate a trusted person such as IT support or a company executive. The goal is to trick an employee into granting system access, installing remote-access software, or revealing credentials.
Which hedge funds were targeted in the August 2026 attacks?
Point72 Asset Management confirmed it was attacked, with early indications no client data was stolen. Attackers also attempted to breach Millennium Management, Two Sigma Investments, and Citadel, along with several private equity firms, as part of the same coordinated campaign. Two Sigma detected and blocked the attempt with no breach.
Is this connected to the law firm attacks from earlier in 2026?
The attack method matches a campaign Google's Mandiant division attributed to a threat cluster tracked as UNC3753, also known as Luna Moth, Chatty Spider, or Silent Ransom Group, which targeted dozens of US law firms and financial services companies between January and May 2026 using the same vishing and remote-access-tool playbook. No formal attribution has confirmed the exact same group carried out the August hedge fund attacks, but the tactics are consistent.
How can a business protect itself from AI vishing attacks?
Four steps matter most: a written and practiced callback verification policy for any request involving system access, a hard rule against granting remote access or credentials over an unscheduled call, phishing-resistant MFA on every entry point, and a no-blame culture that makes employees comfortable reporting a suspicious call immediately rather than staying quiet out of embarrassment.
Why is AI making these attacks more common?
AI has lowered the cost and skill required to run convincing impersonation attacks at scale. Voice cloning that once required real effort and audio samples can now be done with a few seconds of publicly available audio or video. According to cybersecurity experts quoted by Bloomberg, this has moved attackers from being able to realistically target around 50 organizations in a campaign to targeting as many as 1,000.







Comments