Skip to content

Wall Street's Vishing Problem Starts at the Help Desk

Security leaders speaking on this exact vishing threat at an Ai4 cybersecurity panel on Aug. 4 said the best defense against voice-based impersonation is identity verification.

Hackers attempted to breach information systems at Two Sigma Investments, Citadel and Point72 Asset Management, along with several private equity firms, in a wave of attacks in early August, Bloomberg reported Wednesday, citing people familiar with the matter.

The attacks used voice phishing, or vishing, in which callers mimic the voices, tone and phrasing of executives or colleagues to persuade employees to reveal sensitive information or grant system access, according to the report.

Two Sigma, which oversees $75 billion, said it stopped the attempt. A spokesperson told Bloomberg the firm's security team responded quickly and found "no indication of any impact to our data or our systems."

Point72 told investors it had been attacked and that initial indications showed no client information was taken, according to Bloomberg. The firm said it was still reviewing the incident. Spokespeople for Point72 and Citadel declined to say whether hackers reached their systems.

Vinod Paul, president of Align Managed Services, which provides cybersecurity and IT services to hedge funds, told Bloomberg that hackers can listen to a phone call and then reproduce the speaker's voice, tone and phrasing to fabricate convincing fake calls. Attackers who once targeted 50 entities in a campaign can now reach 1,000, he said.

Voice cloning of that kind requires generative AI, and multiple outlets have described the campaign as AI-powered. Bloomberg's sources did not identify the specific tools used, and no group has been publicly linked to the campaign. Mandiant documented AI-powered voice spoofing as an operational vishing technique in 2024, including its use by the firm's own red team.

The Financial Industry Regulatory Authority has contacted member firms about the attempted breaches, according to Bloomberg. FINRA launched its Financial Intelligence Fusion Center in March, a portal for member firms to share fraud threat intelligence and coordinate responses. A FINRA spokesperson declined to comment.

CrowdStrike's 2026 Threat Hunting Report, covering July 2025 through June 2026, recorded twice as many vishing intrusions in the first half of 2026 as in the second half of 2025. Mandiant's M-Trends 2026 ranked voice phishing the second most common initial infection vector for 2025, present in 11% of investigations where a vector could be identified.

Mandiant and the Google Threat Intelligence Group documented a related campaign in a June 5 report. Between January and May, the threat cluster UNC3753, also tracked as Luna Moth, Chatty Spider and Silent Ransom Group, targeted dozens of US professional, legal and financial services organizations.

In that campaign, attackers sent an invoice-themed email from a consumer account to raise the recipient's security concerns, then called posing as internal IT or security staff. Employees were directed to join a screen-sharing session over Zoom, Microsoft Teams or Quick Assist and install a remote monitoring tool such as AnyDesk or Zoho Assist. After exfiltrating data, attackers issued extortion demands within roughly 30 minutes and gave victims three days to pay.

The FBI documented a further escalation in a May advisory. When remote attempts failed, individuals entered corporate offices posing as IT technicians and copied data to USB drives or external hard drives.

Defending against AI vishing attacks

Security leaders speaking on this exact vishing threat at an Ai4 cybersecurity panel on Aug. 4 said the best defense against voice-based impersonation is identity verification. Krista Arndt, associate chief security officer at St. Luke's University Health Network, said her organization has invested heavily in its identity program on the premise that a help desk employee must be able to confirm a caller is who they claim to be, and the caller must be able to confirm the help desk employee actually works there. Arndt said awareness training alone does not hold, because staff are pulled in several directions at once and cannot be relied on to respond consistently. Partha Chakrabarti, global head of security engineering at Broadridge Financial Solutions, said contact that triggers suspicion should be validated out of band, on a separate channel, before any request is acted on.

On technical controls, Chakrabarti cited email authenticity validation — SPF, DKIM and DMARC enforced to a reject policy — along with domain takedowns and FIDO-compliant, spoofing-resistant multifactor authentication. Stephen Franklin, chief executive of NetWatch.AI, said behavioral baselining catches what content inspection misses: after roughly a week of monitoring user and application activity, deviations from an individual's established pattern can be flagged for review. Franklin said his company worked with Verizon and AT&T to obtain verified sender branding on outbound alerts so recipients can distinguish legitimate messages from spoofed ones.

Alaa Abdulridha, engineering director at SerpApi, said the company is building an agent that scores the reputation of the source behind an inbound email or phone call.

Panelists said getting the basics right matters more than tooling. Torrell Funderburk, founder and chief executive of Overspace and a former global CISO, said foundational controls scale better than novel ones, and that organizations attempting to defend everything at once spend heavily without return. Arndt described a risk-tiered approach to automation, keeping a human in the loop for high-impact actions while automating lower-risk ones. Chakrabarti said some actions should be hard-coded as prohibited regardless of what an automated system recommends.

Earlier impersonation attacks have produced larger documented losses. A finance employee at engineering firm Arup transferred roughly $25 million in early 2024 after a video conference in which the other participants were AI-generated, Hong Kong police said.

Deloitte's Center for Financial Services projects that US fraud losses enabled by generative AI will reach $40 billion by 2027, up from $12.3 billion in 2023, under its aggressive adoption scenario. Its conservative estimate is about $22 billion.

HOU.SEC.CON CTA

Latest