AI Voice-Cloning Scams Target Wall Street’s Biggest Hedge Funds

Picture this: your phone rings, and it’s your boss’s voice — same tone, same speech patterns, even the same slight pause before he says your name. Except it isn’t him. It’s an AI clone, and it’s asking you to reset a password or approve access to a system. This isn’t a hypothetical anymore. It just happened to some of the biggest hedge funds in the world.

Here’s exactly what unfolded, why Wall Street has become such an attractive target, and what this means for anyone who works somewhere with money worth stealing.

What Actually Happened

Several of the world’s largest hedge funds — including Citadel, Millennium Management, Two Sigma Investments, and Point72 Asset Management — were targeted this week in a sophisticated, AI-powered voice phishing campaign, according to Bloomberg. Several private equity firms were also caught up in the attacks, though their names haven’t been disclosed.

The attackers weren’t using malware or exploiting software bugs — they were exploiting trust. The attacks relied on voice phishing rather than malware, using AI to impersonate higher-ups or IT support staff to convince employees to reset passwords, share one-time authentication codes, or approve fraudulent access requests.

The response from targeted firms has varied. Two Sigma confirmed it successfully blocked the attempt with no data compromised, stating its security team responded quickly and found no indication of impact to its data or systems. Citadel and Point72, on the other hand, declined to comment on whether they were actually breached.

Regulators are already involved. The Financial Industry Regulatory Authority, or FINRA, has begun connecting affected firms with threat intelligence through its Financial Intelligence Fusion Center, a channel launched in March specifically for sharing fraud intelligence and coordinating responses to sophisticated threats.

Why It’s So Easy to Clone Someone’s Voice Now

The unsettling part of this story isn’t that voice cloning exists — it’s how little effort it now takes to pull off. Training a convincing voice model requires only a few minutes of publicly available audio, the kind that’s readily available from earnings calls, conference panels, podcast appearances, and media interviews. For senior executives at major financial firms, that kind of public audio is everywhere.

The bar has actually dropped even further in recent years. Scammers can now clone a voice using as little as 3 seconds of audio, and more than half of people share voice recordings online at least once a week, which only expands the pool of material scammers can pull from. The sample size needed for a convincing clone has fallen from around 60 seconds in 2023 to just 3 seconds in 2026.

Detection is getting harder too. Modern voice clones can reach around 97% accuracy, and real-time cloning technology can now operate with sub-200-millisecond latency, enabling live, convincing vishing calls rather than pre-recorded clips. That kind of speed is what makes these calls so dangerous — there’s no delay or robotic distortion to tip off a suspicious listener.

Why Wall Street Specifically Has Become a Target

Finance firms haven’t always been the top target for this kind of attack, but that’s shifted. Investment firms have overtaken traditional banking institutions as the most-targeted subindustry in the finance sector, according to Black Kite’s 2026 Financial Services Cybersecurity Report, with attacks on investment firms nearly doubling since 2023. Ransomware attacks on the finance sector overall rose 30% in 2025 and were already up another 76% in the first quarter of 2026 alone, with investment firms accounting for roughly 40% of that activity.

The financial incentive for attackers is enormous, and the track record proves it. In 2025, a multinational firm lost nearly $25 million after employees fell for an AI-cloned CEO voicemail, and before that, a UK energy firm was tricked out of $243,000 in a similar CEO voice-cloning scam. One of the most notorious cases occurred in January 2024, when a finance worker at the Hong Kong office of engineering firm Arup wired $25.6 million to scammers after a video conference featuring deepfaked versions of the company’s CFO and several colleagues.

The broader numbers paint an even starker picture. AI-enabled fraud incidents surged dramatically in 2025, and industry projections suggest generative AI fraud losses could reach $40 billion annually by 2027. Voice phishing attacks specifically surged 442% in 2025 due to AI-driven techniques, and deepfake-enabled vishing attempts jumped over 1,600% in the first quarter of 2025 compared to the previous quarter in the US alone.

These Attackers Have a Track Record

This isn’t some amateur operation testing new tools for the first time. Notable extortion groups, including the Scattered Lapsus$ Hunters trio, have already perfected IT help-desk style attacks against third-party vendors, having carried out month-long breaches of Marks & Spencer and Jaguar Land Rover in 2025. Bringing that same social-engineering playbook to Wall Street, now supercharged with real-time voice cloning, is a natural — and alarming — next step.

How to Protect Yourself and Your Organization

If your job involves handling sensitive access, credentials, or financial approvals, a few practical habits genuinely help:

  • Never approve sensitive requests based on a voice call alone. Even if it sounds exactly like your boss, verify unusual requests through a separate channel — a text, an internal messaging app, or a callback to a known number.
  • Be suspicious of urgency. Scammers rely on pressure and time pressure to short-circuit careful thinking. A legitimate request can almost always wait a few minutes for verification.
  • Set up a verification codeword with your team or family. A simple, pre-agreed phrase that AI can’t guess adds a fast, low-effort layer of protection against impersonation.
  • Limit how much of your voice is publicly available. This is harder for public-facing executives, but reducing unnecessary public audio, especially long-form interviews and unedited panel recordings, reduces the raw material available to clone.

Read More :- LinkedIn Is Skipping AI Data Center Expansion This Year — Here’s Why | Affitronix

Conclusion

The Wall Street voice-cloning campaign is a clear signal that AI-powered social engineering has moved from a theoretical risk to an active, ongoing threat against some of the most well-defended financial institutions on the planet. What makes this wave particularly dangerous isn’t just the sophistication of the technology — it’s how little material attackers now need and how convincingly real these calls sound. As voice cloning keeps getting cheaper and faster to deploy, the real defense isn’t better software alone; it’s a workplace habit of never trusting a voice on the phone as proof of identity, no matter how familiar it sounds.

FAQs

Q1: Which Wall Street firms were targeted in this AI voice-cloning attack?
Citadel, Point72 Asset Management, Two Sigma Investments, and Millennium Management were among the hedge funds targeted, along with several unnamed private equity firms, according to Bloomberg.

Q2: How much audio does it take to clone someone’s voice today?
As of 2026, scammers can create a convincing voice clone using as little as 3 seconds of audio, down from about 60 seconds required in 2023.

Q3: Did any of the targeted firms actually lose money or data?
Two Sigma confirmed it blocked the attempt with no impact to its data or systems. Citadel and Point72 have not confirmed whether they were breached.

Q4: How can employees protect themselves from AI voice-cloning scams?
Never approve sensitive requests based solely on a phone call, even if the voice sounds familiar. Verify unusual requests through a separate communication channel and be wary of any request that pressures you to act immediately.

Scroll to Top