On 5 August 2026, a coordinated wave of AI voice-cloning attacks hit four of the most heavily defended firms in finance: Citadel, Point72 Asset Management (Point72), Millennium Management, and Two Sigma Investments (Two Sigma), along with several unnamed private equity firms. The callers used synthetic audio built from public recordings to reproduce the voice, tone and phrasing of trusted executives and colleagues, phoning employees directly and asking them to hand over credentials or grant system access. No malware, no exploited software flaw. Just a phone ringing with a voice everyone in the room already trusted.
The mechanic behind it is well understood by security researchers. Attackers gather a few seconds of publicly available audio, an earnings call, a conference panel, a podcast appearance, enough to train a real-time voice model on a specific person. They then call an employee with the urgency and authority a senior voice carries inside a hedge fund, asking for a credential reset, a login, an access grant. Because the technology now runs at scale, the same campaign that reached Citadel, Point72 and Millennium could have called a thousand other firms that same afternoon at almost no additional cost. Vinod Paul, president of Align Managed Services, put the shift in economic terms: "Before they could attack 50 entities in a targeted attack, now they can do 1,000."
The damage, so far as anyone will confirm it, is uneven. Two Sigma, which manages roughly USD 75 billion, says it detected and blocked the attempt with no impact to its data or systems. Point72 told investors it had been attacked and that its initial review found no client information stolen, though the investigation continues. Citadel and Millennium Management have declined to comment on whether their defences held. That silence leaves the real scope of the campaign unknown, in a year that has already seen AI-enabled fraud cost the global economy a reported USD 442 billion.
The defences that failed here, to whatever degree they failed, were not weak by conventional standards. These are among the best-resourced security organisations in financial services, firms with dedicated fraud teams, mandatory multi-factor authentication, and, since March 2026, access to FINRA's Financial Intelligence Fusion Center for cross-industry threat sharing. The standard advice for exactly this scenario is a pre-arranged verbal code word: a phrase agreed in advance, over a separate channel, that a caller must supply before any high-stakes action proceeds. It is a reasonable instinct. It is also a shared secret, and a shared secret can be phished, coerced out of someone under pressure, or leaked from a breach somewhere else in the organisation. A code word only holds if the person on the receiving end remembers to demand it in the exact moment the attacker has engineered them not to.
This is where GoFirm's model differs. A credential reset, an access grant, a wire authorisation requested by phone is an execution event. Before it goes ahead, GoFirm sends a real-time push notification to the named authority's own registered device, the actual person the caller claims to be, requiring biometric confirmation before the action is allowed to proceed. No confirmation, no execution. The instruction can arrive by phone, video or email; the confirmation has to come from the device and the fingerprint or face of the real authority, on a separate channel the caller never touches.
A cloned voice, however convincing, cannot produce that confirmation. It can replicate every syllable an executive has ever spoken in public. It cannot make that executive's fingerprint appear on that executive's own registered device. The execution boundary holds regardless of how credible the impersonation sounds on the call.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with www.osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Rutherford, M. 2026. Wall Street hedge funds hit by coordinated AI vishing: FINRA Fusion Center activated. Tech Times, 6 August 2026.
2. InvestmentNews. 2026. Point72, Citadel among hedge funds hit by AI vishing attacks. InvestmentNews, 5 August 2026.
Back to Blog
Case Studies·3 min read
Four Wall Street hedge funds faced the same cloned voice. Only one will say it stopped.
By GoFirm
