Wall Street's biggest hedge funds are dealing with a coordinated cyberattack using artificial intelligence to mimic employee voices over the phone. According to Reuters, hackers deployed AI-generated audio that sounded like trusted staff members, tricking employees into handing over access to internal systems through what security experts call voice phishing or "vishing."

Two Sigma Investments confirmed it detected and blocked the attack before any damage occurred. The firm's IT team shut down the phishing campaign, protecting both systems and data from compromise. But Two Sigma wasn't alone. Ken Griffin's Citadel and Steve Cohen's Point72 Asset Management were also targeted, though both declined to say whether the attackers actually penetrated their networks. Reports suggest unnamed private equity firms got hit too.

How the scam worked

The technology behind the attack is straightforward but effective. Hackers used AI tools to analyze phone conversations, then recreated an employee's voice, speech patterns, and tone. The fake calls sounded convincing enough that staff couldn't immediately tell they were talking to a criminal instead of a coworker. As AI improves, these scams are getting harder to spot. Criminals can now generate realistic voices in minutes, not hours.

The attack landed in the middle of broader regulatory pushes to tighten financial sector security. Earlier this year, the Financial Industry Regulatory Authority launched the Financial Intelligence Fusion Center, letting member firms share cyber threat intel faster. FINRA declined to comment specifically on this incident but confirmed it had already contacted the affected companies. Similar social engineering tactics have surfaced elsewhere in finance, with fraudsters impersonating officials to steal credentials during regulatory transitions.

This article is for informational purposes and does not constitute financial or security advice. Consult your cybersecurity team for specific threats to your organization.