Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
In early August 2026, attackers used AI-cloned voices to target Point72, Citadel, Millennium Management, and Two Sigma, four of the largest hedge funds in the world, in a single coordinated wave. The voices on the calls belonged to executives and colleagues the employees recognized. None of those voices was real.
Most of the attempts failed. Two Sigma, which manages about 75 billion dollars, said it blocked the effort outright, and Point72 told investors its first review found no client data stolen. The reason this still matters, even without a confirmed breach, is what the attackers went after and how cheaply they did it.
The technique is called vishing, short for voice phishing, and the AI twist is voice cloning. Modern synthesis tools can reproduce a specific person's voice, including their tone and phrasing, from a few seconds of audio lifted off an earnings call, a conference panel, or a podcast. The attacker then places a phone call in that voice. In this campaign the calls did not go to the people who move money. They went to the people who control access.
The pattern security teams reconstructed runs like this. Someone calls the IT service desk posing as an employee, sometimes spoofing the caller ID and sometimes speaking in a cloned voice, and says they lost or changed their phone. They ask the agent to remove the multi-factor authentication (MFA, the second login step such as a code sent to your phone) on the account and enroll a new device. If the agent agrees, the attacker now holds the login and the second factor that was meant to protect it. Voice was the proof of identity, and voice is precisely what the attacker forged.
The concrete consequence here is not a stolen fortune, it is a proof of concept run in public. Someone pointed the same play at four rival firms with hundreds of billions under management inside a single week, and a regulator stood up a crisis-coordination center it had never before needed to use in anger. What made that possible is the economics. Vinod Paul of Align Managed Services, which runs security for hedge funds, told Bloomberg that an operation which used to reach 50 targets can now reach 1,000, and that an attacker can listen to a call and mimic the speaker on the next one. The cost of a convincing, targeted voice attack has collapsed. Google's threat intelligence team had already flagged a similar voice-phishing wave against US law firms in June 2026, in some cases with people physically walking into offices posing as IT staff. For your own organization, the exposure is not your CFO being fooled on a video call. It is your help desk. If an agent takes a call tomorrow from an executive who sounds exactly right, says they are locked out, and needs their MFA reset before an important meeting, the security of that account now rests on whether a junior staffer under time pressure follows a script or a familiar voice. The shift underneath all of this is that voice has stopped being evidence of who someone is. Every process that still treats a recognized voice as authentication, from help-desk resets to wire approvals, now rests on a control an attacker can rent by the hour.
No money has been confirmed lost, and most of these attempts were caught. Bring the shape of it to your next security meeting anyway, because it will be repeated against smaller targets with weaker help desks. Attackers cloned trusted voices, skipped the executives, and dialed the people who hand out access, and they ran it against four heavyweight firms at once because AI made doing it a thousand times almost as cheap as doing it once. The question for your own organization is simple: if that call reaches your service desk tomorrow, what stops it, a cloned voice or a verification step that does not care what the caller sounds like?


