Wall Street Vishing Attacks Show Why Financial Institutions Must Prepare for AI-Powered Impersonation

10 minute read

Key takeaways

  • Voice phishing (vishing) attacks recently targeted major hedge funds, including Point72, Citadel, Millennium, and Two Sigma.
  • GenAI tools require as little as 20–30 seconds of publicly available audio to clone a voice.
  • Financial institutions are particularly vulnerable because high-value decisions depend on trusted voice communications and rapid execution.
  • Identity verification alone is no longer enough. Organizations must verify the authenticity of every participant in every high-risk interaction.

Hackers recently launched a coordinated wave of voice phishing attacks against some of the world’s largest hedge funds and private equity firms. The campaign highlights how advances in AI are accelerating this type of social engineering attack.

According to Bloomberg, threat actors targeted firms including Point72, Citadel, Millennium, and Two Sigma by impersonating trusted colleagues and IT personnel over the phone. Their objective was simple: persuade employees to disclose sensitive information or grant access to corporate systems.

In one reported incident, callers posing as members of the IT help desk attempted to obtain the login credentials for employees’ authenticator applications, the very controls designed to strengthen multi-factor authentication. 

While Two Sigma and Point72 both reported no evidence of compromised systems or client data, the campaign signals that even the industry’s most security-conscious firms are now being targeted by AI-powered social engineering.

AI Has Changed the Economics of Deception 

The significance of this campaign isn’t simply that prominent hedge funds were targeted, it’s that financial institutions along with other enterprises should remain wary of trusting voice-based interactions alone.

Until recently, convincing voice phishing campaigns required skilled operators and significant manual effort, limiting both their scale and profitability. Those constraints limited the number of organizations an attacker could realistically target. That is no longer true. 

Modern AI voice cloning has reduced the barriers to conducting highly convincing voice impersonation attacks. High quality text-to-speech and speech-to-text technologies can be integrated with AI agents to enable them to place phone calls and engage in social engineering at scale.

“Most people are unprepared for the experience of receiving a phone call from an AI agent that is bent on social engineering them,” explains Tom Cross, Head of Threat Research at GetReal Security. “Many people’s mental model of state of the art voice agents comes from bad experiences we’ve had trying to interact with them on customer service lines, where they often have limited vocabularies. In fact, agentic social engineering systems can be quite creative and persistent at getting what they are after, and they can be very convincing.”

Attackers no longer have to decide whether to target five organizations or five hundred because AI dramatically reduces the cost of reconnaissance, content generation, and voice impersonation, making coordinated campaigns against multiple high-value organizations economically viable.

The same economics that justify targeting firms like Citadel and Point72 also make it inexpensive to add hundreds of smaller financial institutions to the same campaign.

“Whether you are small or large, the risk is the same,” Kevin Thompson, Founder and CEO of 9i Capital Group, summarized the challenge well when speaking to InvestmentNews. “AI has lowered the cost of deception to the point where every financial institution should assume it is a potential target.”

Why Voice is Becoming the Weakest Link 

Voice phishing—or vishing—uses phone calls or voice messages to impersonate someone an employee trusts. Increasingly, those voices are generated using AI tools.

Attackers don’t need a perfect clone, they need a voice that sounds authentic enough to create confidence, establish authority, and convince someone to take action. 

“An audio deepfake is pretty easy to pull off if you’ve got a sample of maybe 20 or 30 seconds of someone speaking,” reminds Cross. “And for those of us who go out and speak publicly, it’s pretty easy to get that for us. A human being is not going to be able to distinguish these voices from the real voice that they are simulating.”

Organizations can no longer assume employees will reliably recognize when they’re speaking to a synthetic voice. 

Why Financial Institutions Are Especially Vulnerable 

Many of the interactions happening in financial institutions, especially at hedge funds, are happening under significant time pressure. This operating model creates an opportunity for attackers who prey on human vulnerability.

As firms accelerate decision-making, they face a structural challenge. Security requires verification, while financial markets reward speed. AI-powered vishing exploits the tension between the two.

What Financial Institutions Should Do

The response to voice phishing isn’t simply more security awareness training, organizations should assume that convincing voice impersonation can now be powered using AI and is now part of the threat landscape and adjust their processes accordingly.

Security leaders should consider:

  • Requiring independent verification for credential resets, privileged access requests, MFA enrollment, and wire transfers.
  • Communicating official channels and verification procedures for help-desk outreach to employees.
  • Establishing out-of-band confirmation procedures for high-risk requests.
  • Reviewing help desk processes to ensure voice alone is never treated as proof of identity.
  • Exercising AI-powered impersonation scenarios through tabletop exercises and red-team assessments.
  • Deploying technologies capable of detecting synthetic voices and continuously verifying the authenticity of participants during sensitive communications.

Some advisory firms are already introducing additional verification steps before authorizing wire transfers or other high-risk requests, according to InvestmentNews

The challenge for security leaders will be implementing these safeguards without creating unnecessary operational friction and making sure they will be resilient against the next evolution of this threat. 

Trust Must Be Verified, Not Assumed

The Wall Street campaign should be viewed as an early warning of a broader shift. As generative AI continues to separate identity from authentic human presence, attackers will increasingly exploit the gap between authentication and trust, exposing the limitations of identity controls that were never designed to verify authenticity throughout an interaction.

For decades, enterprise security assumed that a successful login meant a trusted human was on the other end of the connection. Generative AI has broken that assumption. A valid credential doesn’t guarantee you’re interacting with the right person, or even a person at all. AI agents are already capable of creating and operating convincing synthetic identities, further blurring the line between authentic users and autonomous actors.

Financial institutions now face a new challenge: extending Zero Trust beyond authentication and into every high-value interaction.

That’s why we believe enterprises need an authenticity layer. GetReal continuously verifies the authenticity of people, communications, and media throughout an interaction. 

    See How GetReal Stops AI Impersonation

Schedule a demo of GetReal Protect