Employees at some of the largest hedge funds are picking up the phone and think they are talking to their boss – but they’re not.
That’s because hackers have launched a coordinated AI voice clone phishing attack targeting investment banks across the country.
The sophisticated attacks, which mimicked key executives’ voices, attempted to trick employees of hedge funds and private equity firms into revealing sensitive information or granting access to company systems.
Bloomberg Reported the Industry-Wide Attack
According to a Bloomberg Report, Point72 Asset Management informed investors on Wednesday that it had been attacked, though the hedge fund’s initial indications were that no client information was stolen, according to one of the people, asking not to be identified, discussing non-public information. The firm told investors it was still reviewing the incident, the person said.

The attackers also attempted to breach Millennium Management, Two Sigma Investments, Citadel, and several other private equity firms.
Two Sigma reported that they were able to stop the attack when they spoke to Bloomberg.
“Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a spokesperson for Two Sigma said in a statement. “We continue to monitor the situation closely.”
Spokespeople for Citadel, Point72 and Millennium declined to comment. FINRA has been in touch with member firms about the attempted break-ins, according to a person with knowledge of the matter cited by Bloomberg.
A spokesperson for FINRA declined to comment.

Will Wilson, chief executive of Antithesis , a software firm backed by Jane Street, told Bloomberg the AI has changed cyber attacks considerably.
“The terrifying thing about modern-day AI systems is that they have commoditized this and made it possible to execute attacks at scale,” Wilson said. “Everybody will have to seriously level up. Otherwise they are going to be in big trouble.”
Google Reported A Wave Of Similar Attacks Against Law Firms This Year
The hedge fund AI cyberattacks follow a pattern that has been running all year.
In June, Google’s Mandiant unit described a campaign by the Silent Ransom Group, called Luna Moth, that hit dozens of law firms and financial companies between January and May.
That campaign was different. The cyberattackers used voice phishing by posing as IT support to trick employees into screen-sharing, so they could take over their computers and infiltrate the network.
The FBI says the group behind those attacks went so far as to send people into offices in person, posing as technicians and plugging in USB drives.
The attacks could not come at a worse time as the US is reeling from cyberattacks on the nation’s water supply.
Special thanks to Ori Eisen, founder and CEO of Trusona for the tip on this story. His firm offers protection on attacks like this with his ATO Protect Solution.