AI-Powered Voice Phishing Campaign Targets Major Wall Street Hedge Funds
Key Takeaways
- •Multiple major Wall Street hedge funds, including Two Sigma, Citadel, and Point72 Asset Management, were targeted in a coordinated AI-driven voice phishing campaign.
- •Attackers used AI voice cloning technology to replicate employees' voices, speaking patterns, and tone to place convincing fraudulent calls to firm staff.
- •Two Sigma Investments confirmed it successfully blocked the cyberattack without any compromise to its systems or data.
- •No system breaches, customer data losses, ransom demands, or financial losses have been confirmed in connection with the attacks.
- •FINRA has reached out to the affected firms and previously launched a Financial Intelligence Fusion Center to help member firms share cyber threat information more rapidly.

A sophisticated AI-driven cyberattack has targeted several of Wall Street's largest hedge funds, with hackers using artificial intelligence to clone employees' voices in an attempt to breach internal systems. According to a Reuters report published on Wednesday, the attackers orchestrated coordinated voice phishing — or "vishing" — campaigns by generating AI-powered voice replicas that impersonated trusted employees, enabling them to place highly convincing fraudulent phone calls to firm staff.
Financial services has long ranked among the most targeted sectors for cyberattacks, but the deployment of AI-generated voice clones marks a notable escalation in social engineering tactics aimed at the industry. The approach mirrors a widely reported 2024 incident in which criminals used AI voice cloning to impersonate a chief financial officer and steal approximately $25 million from the British engineering firm Arup, demonstrating that the technique has already produced real financial losses outside the financial sector.
Two Sigma Confirms It Thwarted Attack
Two Sigma Investments is among the firms that were targeted and has confirmed that it successfully blocked the AI cyberattack before any damage occurred. According to Bloomberg, the firm's IT department was able to neutralize the voice phishing attempt without any compromise to its systems or data. Two Sigma is reported to be one of multiple companies whose systems were targeted in the campaign.
Citadel and Point72 Among Targeted Firms
Bloomberg also reported that Ken Griffin's Citadel and Steve Cohen's Point72 Asset Management were on the list of targeted organizations. Both firms declined to comment on whether the attackers succeeded in accessing their systems. The report additionally noted that several unnamed private equity firms were subjected to similar voice phishing attempts.
AI Voice Cloning Technology Enabled the Attacks
The cyberattack reportedly leveraged technology capable of capturing phone conversations and reproducing a person's voice, speaking patterns, and tone. This allowed attackers to place realistic phone calls that appeared to originate from trusted internal employees.
Cybersecurity experts note that AI-powered scams are becoming increasingly difficult to detect as the underlying technology improves. Criminals can now produce convincing fake voices in minimal time, significantly reducing the ability of employees to distinguish between a legitimate caller and a fraudster. Security professionals increasingly recommend callback verification protocols and multi-factor authentication as baseline defenses against such schemes.
FINRA's Response to AI Cyber Threats
The incident comes as financial regulators continue working to strengthen cybersecurity standards across the industry. Earlier this year, the Financial Industry Regulatory Authority (FINRA) launched the Financial Intelligence Fusion Center, a platform designed to enable member firms to share information about cyber threats more rapidly.
FINRA declined to comment on this specific AI cyberattack. However, a spokesman cited by Bloomberg confirmed that the regulatory body had already reached out to the affected firms. The episode also intersects with Securities and Exchange Commission cybersecurity disclosure rules that took effect in late 2023, which require publicly traded companies to report material cybersecurity incidents within four business days — a framework that could shape how affected firms handle any future breach that crosses the materiality threshold.
Will Wilson, CEO of the IT security firm Antithesis, observed that advances in artificial intelligence have substantially lowered the barrier to executing such cyberattacks. He emphasized that attacks which once required significant hacking expertise can now be deployed at scale thanks to AI tools. Wilson urged financial institutions to reinforce their IT security infrastructure.
No Confirmed Breaches or Financial Losses
As of now, no system breaches, customer data losses, ransom demands, or financial losses have been confirmed in connection with the AI cyberattack.
The event highlights the escalating risk that AI-based cyberattacks pose to the financial sector. With Wall Street institutions processing billions of dollars in transactions daily, security experts emphasize that firms will need increasingly advanced defensive systems to keep pace with rapidly evolving AI capabilities.