Hedge Funds Thwart AI Voice‑Phishing Campaign

Point72, Millennium, Citadel and Two Sigma say they repelled a coordinated AI‑enabled voice‑phishing effort aimed at staff to obtain credentials or system access.

Several large hedge funds reported that they repelled a coordinated campaign in recent weeks that used AI‑generated voice impersonations to try to gain employee credentials and access to internal systems. The firms involved include Point72 Asset Management, Millennium Management, Citadel and Two Sigma; several private equity firms were also targeted.

The attackers used synthetic speech to mimic trusted voices during calls or voice messages and to persuade employees to disclose passwords or grant system access. The incidents focused on phone‑based social engineering, commonly called “vishing.”

Point72 notified investors that it detected an attempted breach and said an initial review found no client information was compromised; the firm is continuing its investigation and declined to speak publicly. Two Sigma confirmed it blocked an attempted intrusion. Millennium and Citadel declined to comment.

Regulators and industry groups were informed of the attempts. The Financial Industry Regulatory Authority has communicated with member firms about the incidents. Earlier this year the regulator established a Financial Intelligence Fusion Center to improve intelligence sharing and coordination on cyber and fraud threats affecting the securities industry.

Cybersecurity specialists point to advances in generative AI that make voice‑phishing campaigns more scalable and convincing. Vinod Paul, president of Align Managed Services, warned that “AI now enables attackers to launch targeted campaigns against hundreds or even thousands of organisations simultaneously, while also creating increasingly convincing voice impersonations.”

Researchers flagged a rising trend in AI‑assisted vishing in recent months, noting campaigns that targeted professional services firms and, in some cases, attempted to gain physical access by impersonating IT staff.

Firms in financial services are reviewing incident response procedures, tightening verification protocols for voice contact and increasing employee training on how to handle unexpected requests. Companies are also sharing indicators of attack through industry channels to help detect and block similar attempts.

Articles by this author