Hackers targeted major Wall Street money managers with cloned voices


Cybersecurity threats targeting Wall Street have risen sharply over the past year, driven by AI tools that enable bad actors to carry out attacks cheaply – and at scale. — Photo by Robb Miller on Unsplash

In recent days, a string of coordinated cyberattacks has hit several major Wall Street money managers. The attacks used voice phishing, a technique that relies on technology to mimic voices in phone calls or messages, tricking employees into handing over sensitive information or granting system access.

“Unlike traditional phishing, AI-powered voice attacks are drastically harder to detect,” George Gerchow, chief security officer at Bedrock Data and faculty at IANS Research, told Inc. “By harvesting vast amounts of personal data from social media and the web, AI can accurately mimic a target’s voice, interests, and behaviour to craft convincing deepfakes.”

The scheme didn’t stop there. Attackers also went after a number of high-profile firms, including Millennium Management, Two Sigma Investments, and Citadel. Two Sigma, which manages US$75bil (RM306.94bil) in assets, confirmed it stopped the attempt before any sensitive data was accessed.

“Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a spokesperson for the company said in a statement to Bloomberg. “We continue to monitor the situation closely.”

This is the same type of scheme used in the recent Levi Strauss cyberattack, which was also reported this week, suggesting this style of attack is spreading well beyond the financial sector.

Why cybersecurity threats are on the rise

Cybersecurity threats targeting Wall Street have risen sharply over the past year, driven by AI tools that enable bad actors to carry out attacks cheaply – and at scale. According to T.J. Marlin, CEO of Guardrail Technologies, hedge funds are targeted for a specific reason. “They have highly sensitive personal information, information that’s valuable to criminals, organisations, etc.,” he told Inc.

However, he added that while this type of hack isn’t new, AI has fundamentally changed who can pull it off, and how many people they can target at once. “Help desk impersonation is decades old,” he said. “What’s really changed here is that with AI going mainstream and available to consumers, and consumers include bad actors, the price of conducting these attacks has made it really scalable.”

Frank Teruel, the COO of Arkose Labs, added that what’s changed is that AI has turned trust into something that can be manufactured at scale. Attackers no longer need to script a single convincing call. Now, they can personalise each conversation on the fly and adapt in real time to how a target responds, all at essentially no additional cost.

It only takes a few seconds to pull someone’s voice from a social post, a webinar clip, or a LinkedIn video. From there, AI can replicate their exact tone and speech patterns. That precision, he said, is what makes the impersonation so hard to catch.

“This is the pattern we’re seeing across modern attacks: AI isn’t just inventing new forms of fraud – it’s making familiar ones dramatically more efficient and effective,” he said.

To stay ahead of attacks like this, both Teruel and Marlin say the fix is building safeguards that don’t rely on human judgment in the moment. Teruel said any request involving money or sensitive information now needs independent verification, even if it appears to come from the CEO, since “authentication and trust are no longer the same thing.”

Marlin agreed. He added that companies need to “move the verification burden off the human” by using confirmation systems, like a callback through a separate channel, that an impersonator wouldn’t have access to. – Inc./Tribune News Service

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

US judge rules Meta hid evidence in Australian tycoon fake ad case
Memphis AI data centre fuels pollution fight in Black neighbourhood
Google’s�AI team tells job seekers its HR filters are unreliable
Zuckerberg manifesto sketches out Meta's ambitions for world-changing AI technology
Apple’s glass-centric 20th-anniversary iPhone remains on track for 2027
Chinese AI drives price competition among US labs
Hack of supposedly safe Bitcoin tool tries faith of the devoted
SEC settles charges over SpaceX, Klarna, pre-IPO share fraud
US SEC exempts certain data center bonds from key securitization rules
US court rules Meta, other tech firms must face thousands of lawsuits over social media addiction

Others Also Read