AI-powered voice phishing hit Point72, Millennium, Two Sigma and Citadel this week, exposing how AI scaled a once-manual fraud technique.
AI-powered voice phishing hit Point72, Millennium, Two Sigma and Citadel this week, exposing how AI scaled a once-manual fraud technique.

A coordinated AI voice phishing campaign hit Point72, Millennium, Two Sigma and Citadel this week, targeting Wall Street's largest money managers.
"Before they could attack 50 entities in a targeted attack, now they can do 1,000," Vinod Paul, president of Align Managed Services, a cybersecurity firm specializing in hedge fund clients, said. "Hackers can also listen into a phone call and mimic the voice, tone and phrasings of the speakers to create fake calls."
Two Sigma, which manages $75 billion in assets, said it blocked the attempt with no data or systems compromised. Point72 told investors Wednesday it had been attacked, though an initial review found no client information stolen. Millennium and Citadel declined to comment. Several private equity firms were also targeted in the same campaign, according to Bloomberg.
The incidents mark the latest escalation in AI-driven social engineering against financial services firms, following breaches this year at Mariner (nearly 9,000 individuals affected), Mercer, Hightower, Edelman Financial Engines and others. FINRA has been in contact with member firms about the attempted breaches, and its Financial Intelligence Fusion Center — launched in March as a threat-sharing portal — is coordinating responses as the industry braces for further AI-enabled attacks.
The "vishing" technique — voice phishing — uses AI tools to clone a real employee's voice, tone and speech patterns closely enough to talk past a colleague on the phone. Attackers then persuade staff to surrender credentials or grant system access. Google's cybersecurity unit flagged a similar wave of vishing attacks targeting law firms and professional services companies in June, with some cases involving fraudsters physically entering offices posing as IT workers.
Will Wilson, chief executive of Antithesis, a software firm backed by Jane Street, said AI has restructured the economics of cyberattacks. "The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale," Wilson said. "Everybody will have to seriously level up. Otherwise they are going to be in big trouble."
Attack costs fall, compliance costs rise
The cost reduction is dramatic. Paul said attackers who once needed weeks to manually target 50 organizations can now reach 1,000 with the same effort — a 20x scale-up. That means financial firms of all sizes, not just the largest hedge funds, face exposure to sophisticated voice fraud.
The regulatory response is taking shape. FINRA's Financial Intelligence Fusion Center, launched in March, provides a secure portal for member firms to share fraud threat intelligence. The regulator has been in contact with member firms about the recent attempts, according to a person with knowledge of the matter.
The incidents also carry implications for the cyber insurance market. Carriers have split since January between policies that explicitly exclude AI-generated deepfake fraud and those writing it in as an affirmative grant. For hedge funds and asset managers moving large sums on the back of a phone call, the question of whether social engineering language responds to a voice clone — rather than a hacked email account — is becoming a central underwriting issue.
Dimon builds cross-sector AI defense
Separately, JPMorgan Chase chief executive Jamie Dimon has been personally calling CEOs at more than 40 companies across banking, energy, water, telecoms, airlines and rail, inviting them to join an expanded Alliance for Critical Infrastructure. The group, which JPMorgan helped establish with Mastercard and Berkshire Hathaway Energy, aims to give members a shared read on AI risk across critical infrastructure and a unified voice in Washington on AI policy.
The private-sector push runs alongside the federal "Gold Eagle" initiative, launched in July, which brings AI developers, infrastructure operators and federal agencies together to share information on vulnerabilities.
For investors, the takeaway is clear: cybersecurity spending is set to accelerate across financial services. The global cyber insurance market, estimated at $16 billion to $20 billion in premium by Gallagher, is forecast to reach $30 billion to $50 billion by 2030. Each major incident like this one tightens the underwriting picture and raises the cost of inadequate defenses.
This article is for informational purposes only and does not constitute investment advice.