Point72, Citadel, Two Sigma Hit by AI Vishing: How the Attacks Worked

A breakdown of the AI vishing attacks that targeted Point72, Citadel, and Two Sigma, plus how to train employees to stop voice phishing.

In early August 2026, some of the largest money managers on Wall Street spent a few tense days fending off the same kind of attack. Hackers ran a coordinated wave of voice phishing calls against major hedge funds, including Point72 Asset Management, Citadel, Millennium Management, and Two Sigma Investments, along with several private equity firms. The callers were not reading from a clumsy script. They used AI to mimic the voices, tone, and phrasing of people the targets trusted, then tried to talk employees into handing over access or sensitive information.

Most of the attempts were caught. Two Sigma said it blocked the campaign with no impact to its data or systems, and Point72 told investors that its initial review found no client information had been stolen. But “we stopped it this time” is not a security strategy, and the incident is a clear signal for every security leader in finance. What follows is how the attacks actually worked, why AI has made this class of attack cheap enough to run at scale, and the layered defenses and training that hold up against a convincing voice on the phone.

Key Takeaways

  • A coordinated AI vishing wave targeted Point72, Citadel, Millennium, and Two Sigma in early August 2026. Most attempts were thwarted, and none of the named funds has confirmed a data breach.
  • The attacks used AI voice cloning to impersonate trusted voices and pressure employees into granting access or sharing sensitive information.
  • AI flipped the economics of these campaigns. Targeted attacks that once reached roughly 50 firms can now reach 1,000, putting the entire financial sector in scope.
  • Caller ID and a familiar voice are no longer proof of identity. Durable defense depends on out-of-band verification and phishing-resistant MFA, not employee vigilance alone.
  • Generic awareness training does not hold up against an adaptive AI caller. Realistic vishing simulation, help-desk identity proofing, and a blameless reporting loop are what actually change behavior.

What Happened: The Hedge Fund Vishing Wave

According to reporting from Bloomberg, later corroborated by Reuters and others, attackers spent several days in early August attempting to infiltrate the information systems of major hedge funds and private equity firms. The common thread was vishing, short for voice phishing: phone calls engineered to trick employees into granting system access or surrendering credentials and other sensitive data.

The named targets read like a roster of the industry’s heavyweights. Point72 informed investors that it had been attacked, though the firm said its early review indicated no client information was stolen and that it was still reviewing the incident. Two Sigma, which manages about $75 billion in assets, said its security team responded quickly and saw no sign of impact. “Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a spokesperson said, adding that the firm continued to monitor the situation. Spokespeople for Point72, Citadel, and Millennium declined to comment.

Regulators noticed. The Financial Industry Regulatory Authority (FINRA) has been in contact with member firms about the attempted breaches, according to InvestmentNews, citing Bloomberg. That outreach fits a pattern of rising concern: FINRA launched its Financial Intelligence Fusion Center in March 2026 as a secure portal for member firms to share fraud threat intelligence and coordinate responses.

The important detail is what did not happen. These were attempted and, by the firms’ own accounts, largely thwarted attacks. No confirmed data breach has been tied to the named funds. That is the difference between a well-drilled organization and a headline, and it is worth studying exactly how the attack is supposed to unfold so you can find the same break points in your own environment.

Attack Breakdown: How an AI Vishing Call Actually Works

A modern AI vishing operation is closer to a small campaign than a single phone call. It runs on a script, research, and a clear objective. Broken into stages, it looks like this.

Target and role selection. Attackers do not call at random. They pick roles with useful access or authority: help-desk and IT staff who can reset credentials, operations and finance employees who can move money or approve access, and people close to executives. In a hedge fund, that short list controls a lot of power.

Pretext and reconnaissance. Before dialing, attackers assemble a believable story. Public sources, leaked data, social media, and prior breaches supply names, reporting lines, vendor relationships, and the internal vocabulary that makes a caller sound like an insider. AI-assisted research makes gathering and organizing this material faster than it used to be. The result is a pretext specific enough to survive the first few skeptical questions.

Voice cloning. This is the step AI has changed most. With a short sample of someone’s speech, pulled from an earnings call, a conference talk, a podcast, or even an intercepted call, attackers can generate audio that carries a target’s voice, tone, and characteristic phrasing. Vinod Paul, president of Align Managed Services, described the capability bluntly to Bloomberg: attackers “can also listen in to a phone call and mimic the voice, tone and phrasings of the speakers to create fake calls.” Treat cloning as the established enabling technology behind this class of campaign rather than a claim about every second of every call.

The call. With a persona and a cloned voice in place, the attacker applies pressure. The playbook leans on authority (“this is the CFO’s office”), urgency (“the auditors need this in the next ten minutes”), and plausibility (details only an insider should know). The goal is to push the target into acting before they verify.

The ask. The request is engineered to look small. Read back a one-time passcode. Approve the multi-factor prompt that just appeared. Reset a colleague’s credential because they are “locked out before a deadline.” Install a remote support tool so IT can “fix” something. Each of these hands the attacker a foothold without ever touching a technical vulnerability.

The pivot. Once inside, the attacker moves toward the real objective: access to trading, wire, or data systems, or a durable presence they can escalate later. This is where the human error becomes a system compromise, and where a firm’s segmentation, privilege limits, and monitoring decide how far the damage spreads.

The reason this attack chain matters is that it breaks cleanly at several points that have nothing to do with how alert any single employee feels. A verification step the attacker cannot satisfy, an MFA method that cannot be read aloud or approved by mistake, or a help-desk procedure that refuses to reset a credential on a caller’s say-so will each stop the sequence cold. That is the thread the defense section pulls on.

Why AI Flipped the Economics of Vishing

Voice phishing is not new. What changed is the cost. For most of its history, a convincing impersonation call required a skilled operator, real preparation, and time, which naturally capped how many targets an attacker could pursue. AI removed that cap.

Paul put numbers on the shift: “Before, they could attack 50 entities in a targeted attack. Now they can do 1,000.” When persona research, script writing, and voice generation are automated, the marginal cost of the next target falls toward zero, and a boutique operation can run campaigns at a scale that used to require an organized crew.

Will Wilson, chief executive of Antithesis, framed the same point in terms of skill. For decades, he told Bloomberg, the financial industry “got away with lax software practices because the skill and knowledge required to execute attacks were specialised and rare.” Modern AI, in his words, has “commoditised this and made it possible to execute attacks at scale.” The barrier that used to protect firms, that good attacks are hard, is eroding.

There is a second-order effect that matters more than the raw volume. AI vishing quietly retires two trust signals that employees have relied on for years. Caller ID can be spoofed, and it always could, but a familiar voice used to be a reasonable proxy for identity. It no longer is. When the voice on the line can be synthesized and the number can be faked, the phone becomes an unauthenticated channel, and any process that treats “they sounded like our CFO” as verification is now a liability.

Why Hedge Funds and Financial Firms Are in the Crosshairs

Attackers go where the advantage is, and few environments concentrate it like a large money manager. These firms move enormous sums through a small number of authorized people and systems, which means a single successful call can put an attacker one step from a wire, a trading platform, or a trove of sensitive investor data. Wall Street handles trillions of dollars in daily transactions, and that flow is exactly what makes the sector attractive.

The hedge-fund wave also sits inside a broader run of attacks on financial services in 2026. Investment advisers have been hit repeatedly by AI-driven social engineering this year. Mega-RIA Mariner disclosed a cloud breach affecting nearly 9,000 individuals, and Mercer has faced class action litigation following a breach linked to the ShinyHunters group. Other firms named in this year’s incidents include Hightower, Edelman Financial Engines, Betterment, and Cetera. The through-line is that attackers have identified the financial sector, and the people inside it, as a reliable, high-value target.

Regulators are responding to that pattern, not just the latest headline. FINRA’s Financial Intelligence Fusion Center, launched in March 2026, exists precisely because cyber and fraud threats aimed at financial firms have grown more sophisticated and more coordinated. For security leaders, the regulatory attention is a useful lever: it makes the case for investment in controls and training easier to make internally, because the expectation of a serious defense is now external as well.

The Precedent: Help-Desk Vishing and the Scattered Spider Playbook

If the hedge-fund wave feels familiar, that is because the core technique has a track record. Reuters noted that the phone-call tactic remains widely used because it works, and pointed to Scattered Spider, a loose-knit group of young hackers that has compiled a long list of corporate victims. No group has been publicly confirmed as the actor behind the hedge-fund campaign, so treat Scattered Spider as a well-documented example of the playbook rather than a named culprit here.

That playbook has made the IT help desk the new perimeter. The pattern is consistent across public advisories from CISA and analyses from firms like Rapid7: an attacker calls the service desk posing as an employee, often spoofing caller ID and sometimes using a cloned voice, claims to have lost or changed a phone, and asks the agent to remove existing multi-factor authentication and enroll a new device, or to send a reset link somewhere new. If the agent complies, the attacker inherits the account. How these help-desk calls are engineered to reset MFA is a well-understood path, and it bypasses email defenses entirely because it never sends an email.

The tactic is also portable across industries. In June 2026, Google’s threat intelligence unit published a post flagging a wave of vishing attacks against U.S. law firms and other professional services companies. Some of those attacks went further than the phone, with individuals physically entering corporate offices while posing as IT workers. The lesson for hedge funds is that the same social-engineering machinery aimed at law firms in June was pointed at money managers in August, and it will move to whichever sector offers the best return next.

Layered Defense: Separate Employee Judgment From Process Controls

The most common mistake in responding to vishing is to make it entirely the employee’s problem. Awareness matters, but a defense that depends on every person catching every convincing call on their worst day will eventually fail. The durable approach splits the problem: build process and identity controls that do not rely on human judgment, then train people to work inside them.

Start with the controls that remove the attacker’s advantage:

  • Out-of-band callback verification. For any sensitive request that arrives by phone, verify the caller through a separate, trusted channel before acting. The key detail is that the callback number must come from an internal directory or identity system, never from the number the caller provides. This alone defeats a spoofed caller ID and a cloned voice, because the attacker does not control the channel you use to check.
  • Phishing-resistant MFA. Move privileged users, help-desk staff, and executive-adjacent roles to FIDO2 security keys or passkeys where practical. Their advantage against vishing is structural: there is no code to read aloud and no push notification to approve by mistake, so a caller cannot talk a user through handing over the second factor.
  • Help-desk identity proofing. Treat credential and MFA resets as high-risk transactions. Require verification against a source the caller cannot easily fake, and consider multi-person or manager approval, or a verified video or in-person check, for resets on sensitive accounts. Because the help desk is the target, its procedures deserve the most rigor.
  • Least privilege and monitoring. Limit what any single compromised account or remote-support session can reach, and watch for the tell-tale pivots: unexpected remote-access tool installs, MFA device changes, and logins from new locations. These narrow the blast radius when a call does get through.

People are the other half of the system, and they perform best when the process gives them permission to slow down. Build a culture where verifying a request is expected rather than rude, where “let me call you back through the directory” is the normal response to any pressure on the phone, and where reporting a suspicious call is fast, routine, and never punished. When an employee who almost fell for a call reports it immediately, the security team can warn everyone else and blacklist the number before the next attempt. That reporting reflex is a control in its own right, and it only exists if people are trained to use it and trusted when they do.

Training Employees to Recognize and Report Voice Phishing

The generic awareness training most firms already run does not prepare anyone for an adaptive AI caller. A slide deck that says “be careful of suspicious calls” teaches recognition of a threat that no longer sounds suspicious. When the voice is familiar, the details are accurate, and the pressure is real, employees need practiced reflexes, not remembered facts. That is a gap realistic simulation fills, and it is where a tool like Brightside earns its place in a program.

Brightside is an AI-era security awareness platform built around simulation, and its vishing simulator is designed to reproduce the attack described above rather than a caricature of it. Programs can run voice-only calls or hybrid scenarios that pair a call with a trackable phishing email, which mirrors the multi-channel way real campaigns operate. Each simulation is assembled from an attack goal, a caller persona, a social-engineering tactic, and a chosen voice, and the platform can generate a caller persona, an opening message, and a recommended strategy so security teams can stand up believable scenarios without scripting every line by hand. Urgency and tone are configurable, and simulations can be previewed in the browser before launch.

For executive-impersonation drills, Brightside supports custom voice cloning from a short recording so a scenario can carry the specific voice an attacker would try to fake. That capability calls for governance: cloning should be used with the consent and awareness of the person whose voice is modeled, and kept inside the training program. Used that way, it lets a firm rehearse the exact “the CFO is calling” pressure that generic training cannot approximate.

The point of all this realism is behavior change, and that requires measurement and follow-through. A vishing metrics dashboard tracks answer rates, failure rates, call duration, and trends over time, so a program can target the roles and behaviors that need work rather than blanketing everyone with the same content. When an employee fails a simulation, Brightside can trigger follow-up training tied to what actually happened on the call, turning a near-miss into a specific lesson.

Recognition is only half the reflex; reporting is the other half. Brightside’s Report Phishing add-on gives employees a one-click way to flag a suspicious message, routing genuine threats to the security team with full headers within seconds while crediting catches on training simulations back to the employee. Pairing realistic vishing drills with a fast, blameless reporting path builds the two habits that stop these campaigns: verify before acting, and raise your hand the moment something feels off. For a deeper walkthrough of building this into a program, Brightside’s guides on stopping voice phishing and training employees against AI voice scams go further than this article can.

Frequently Asked Questions

What is vishing, and how is AI voice cloning changing it? Vishing, or voice phishing, is a social-engineering attack delivered by phone, in which an attacker impersonates a trusted person to trick an employee into granting access or sharing sensitive information. AI voice cloning changes the threat by letting attackers synthesize a specific person’s voice, tone, and phrasing from a short audio sample. That removes one of the last informal trust signals employees relied on, since a familiar-sounding voice is no longer evidence that the caller is who they claim to be.

Were Point72, Citadel, or Two Sigma actually breached? Based on the firms’ own statements, no. These were attempted attacks. Two Sigma said it blocked the campaign with no impact to its data or systems, and Point72 told investors its initial review found no client information was stolen, though it was still reviewing the incident. Citadel and Millennium declined to comment. As of reporting, none of the named funds has confirmed a data breach.

Why are hedge funds and financial firms being targeted with vishing now? Two reasons converge. Financial firms concentrate money and access among a small number of authorized people, so a single successful call can lead straight to a wire, a trading system, or sensitive investor data. At the same time, AI has driven down the cost of running convincing impersonation campaigns, so attackers can pursue far more targets than before. High value plus low attacker cost makes the sector an obvious focus.

How can employees tell a cloned-voice call from a real one? They often cannot, and that is the point. A good clone will sound right, and attackers pair it with accurate details and time pressure. Rather than trying to detect the fake by ear, employees should rely on a process: any sensitive request made by phone gets verified through a separate, trusted channel, such as calling the person back on a number from the internal directory, before any action is taken.

What is the single most effective control against help-desk vishing? If you can implement only one thing, require identity verification that the caller cannot fake before any credential or MFA reset, ideally combined with phishing-resistant MFA such as FIDO2 keys or passkeys for privileged and help-desk accounts. Because the help desk is where attackers aim to reset access, tightening that one procedure removes the most direct path from a phone call to a compromised account.