Stay ahead of the curve with the latest news, ideas and resources on all things Identity Assurance and Passwordless.
Thwarting the AI Vishing Attacks That Targeted Point72, Citadel, Two Sigma and More
Anton Gurov, CISO
9 Min. Read | August 6, 2026
Point72, Citadel, Millennium Management and Two Sigma were all hit this week in a coordinated AI vishing campaign, according to InvestmentNews, also published in Bloomberg, Reuters, and other leading media. Attackers used cloned voices to impersonate IT staff and colleagues, calling help desk agents directly and pressuring them into resetting credentials and account access in real time. As AI erodes our ability to distinguish real from fake, removing human subjectivity from identity decisions is increasingly a security imperative.
How Vishing Attacks Work
Vishing(voice phishing), is a social engineering attack where a bad actor calls an employee, impersonates a trusted colleague or executive and manipulates them into bypassing security controls to reset a credential or grant account access. By mimicking the exact voice of an executive the employee is wired to trust, and making a request that sounds routine, the attacker is quickly handed all access they requested.
Current reports on this specific attack confirms two distinct versions of the same impersonation:
- The attacker poses as the firm's own help desk. The Financial Times reported that at one of the targeted hedge funds, the cyber criminals impersonated the firm's help desk itself, calling employees rather than the other way around. The employee believes they are talking to internal IT or security, not an adversary.
- The attacker poses as a colleague. Multiple outlets, including Insurance Business, reported that attackers used AI-generated voices to clone the tone and speech patterns of real colleagues closely enough to talk staff into handing over access, the classic vishing pattern of an urgent, familiar-sounding voice asking for a favor.
Both versions exploit the same gap. And these calls feel common, nothing alarmingly out of the ordinary from their day-to-day job, whether that job is answering a help desk ticket or picking up when a colleague calls in a hurry. The attacker's entire strategy is to make the interaction feel procedural and unremarkable, so the instinct to help outweighs any instinct to question.
Why Help Desk Agents Are the Primary Target
Help desk agents did not sign up to be a firm's last line of defense against nation-state-grade voice cloning. Their job is to move quickly, be helpful and resolve issues under pressure, often while being measured on call time and ticket resolution speed. Attackers know this. They exploit the exact traits that make someone good at the job: responsiveness, empathy and a bias toward trusting the person on the other end of the line.
When one of these attacks succeeds, the instinct is to blame the agent. That is simply unproductive. The agent was asked to do something no human can reliably do at scale: distinguish a real voice from a convincing fake, in real time, under time pressure, with no tooling to independently confirm who is actually calling. Firms have poured budget into security awareness training for years. That training was built for a world where a suspicious email had bad grammar and a spoofed caller sounded slightly off. AI-cloned voices do not sound slightly off, because they are built from real audio of the person they are impersonating.
Asking an agent to "trust their gut" against that is not a security control, and it is setting someone up to take the blame for a gap in the identity architecture around them.
Why Security Awareness Training Cannot Stop AI Vishing
Every additional training module, phishing simulation and verification script written for help desk agents assumes the same thing: that a human can be taught to reliably catch a fake in real time, forever, no matter how good the fake gets. That assumption was already shaky. Against AI voice cloning deployed at the scale described in this week's attacks, it is no longer defensible.
The firms named this week are not under-resourced or careless. They have serious security budgets and trained teams. The attack worked anyway, because it was a test of whether a human being was still the final decision point for identity verification. As long as that answer is yes, this keeps happening, to these firms and every firm like them, regardless of how much additional training gets rolled out after each incident.
The only durable fix is removing the human decision from the equation entirely. Not making the agent more careful. Not adding another script to follow. Replacing the moment where a person has to judge a voice with a system that verifies identity on its own, every time, without asking anyone to guess.
Removing Human Subjectivity from Identity Decisions
This is exactly the gap HYPR Affirm was built to close. Affirm takes the identity decision away from the help desk agent and puts it in front of the actual person making the request, using document verification, facial recognition with liveness detection, geolocation checks and context-based attestation. Organizations can apply the appropriate multi-factor verification verification workflow based on the user, request and risk.
A help desk agent using Affirm is no longer asked to decide if a caller sounds legitimate. Working where they already are (ServiceNow, Jira, or other ticketing systems), HYPR Affirm is actioned to verify the person is who they claim to be before any reset, recovery or access change happens. There is no judgment call to get wrong, because the agent is no longer the one making the call. The identity is proven or it is not.
This protects the agent as much as it protects the firm. Nobody has to carry the weight of guessing right against an AI-cloned voice, call after call, for the rest of their career.
How This Same Attack Pattern Has Hit Other Industries
Hedge funds are not the first target and they will not be the last. The same voice-impersonation playbook, someone posing as IT, a help desk or a colleague to talk their way past an identity check, has already worked across a run of industries with real money and real budgets behind their security programs:
- Insurance. Erie Insurance and Aflac were both breached over the past year by threat actors associated with Scattered Spider, a group built almost entirely around social engineering rather than technical exploits.
- Hospitality and gaming. The 2023 MGM Resorts breach, still one of the most cited examples in the industry, started with a ten-minute call to a help desk impersonating an employee.
- Law firms and professional services. Google's Threat Intelligence Group flagged a wave of vishing attacks against law firms and professional services companies this year, including cases where attackers physically posed as IT workers to gain building access, not just phone access.
- Financial services, now. Point72, Citadel, Millennium, Two Sigma and several private equity firms, hit by the same underlying technique, adapted with AI voice cloning to work at a scale none of the earlier incidents had.
Different industries, different targets, same repeatable attack playbook every time: a human being asked to verify another human's identity in the moment, with nothing but a voice and a plausible story to go on.
What Enterprises Across Industries Need to Do Now
- Take help desk and recovery verification out of the conversation entirely. If identity is being confirmed through a phone call, a script or a knowledge-based question, it is guessable and it is a target.
- Bind every recovery and reset action to proof, not assertion. Document verification, biometric liveness and device context should confirm who someone is before any credential is touched, not after a story sounds believable.
We recognize that security leaders and IT teams are being asked to respond to an accelerating list of threats with limited time and resources. The last thing organizations should have to do right now is spend weeks evaluating whether this specific gap deserves attention while attackers are already exploiting it.
HYPR is offering free use of HYPR Affirm through October 30, 2026 for affected hedge fund or financial services firms ready to take this decision out of their help desk's hands now. Deploy it against your real recovery and help desk workflows and see these calls get stopped before they start.
Firms that want to move forward can commit to purchase by October 31, 2026. Firms that do not can walk away. Either way, you are protecting this frontline security gap that is under attack, and giving help desk agents the ability to stop being asked to do a job no human can do reliably.
Request your free HYPR Affirm deployment today and take the guesswork off your team before the next call comes in.
Frequently Asked Questions
Who were the attackers pretending to be in the hedge fund vishing attacks?
Reporting on the campaign shows two versions of the same tactic. At one targeted hedge fund, the Financial Times reported that attackers impersonated the firm's own help desk when calling employees. Other reporting, including Insurance Business, described attackers using AI-cloned voices to impersonate colleagues closely enough to talk staff into handing over access.
Is this the first time attackers have used voice impersonation like this?
No. The same playbook with someone posing as IT, a help desk or a colleague to bypass identity verification, has hit many companies. Organizations like Erie Insurance and Aflac have been compromised by the cybercrime group Scattered Spider, MGM Resorts suffered a major attack in 2023 through a help desk impersonation call, and law firms and professional services firms have been impacted this year according to Google's Threat Intelligence Group. Hedge funds are the latest sector, not an isolated case.
Why can't help desk agents just be trained to catch these calls?
AI-cloned voices are built from real audio of the person being impersonated and do not carry the tells of older scam calls. Training assumes a human can reliably detect a fake voice in real time under pressure, indefinitely, which is not a realistic expectation as voice cloning quality improves.
Is it the help desk agent's fault when one of these attacks succeeds?
No. Agents are trained and incentivized to be responsive and helpful, and attackers deliberately exploit those traits. The failure is in an identity architecture that still relies on human judgment as the final check, not in the individual answering the call.
What actually stops AI vishing attacks against help desks?
Removing the human decision point entirely. Automated identity verification, using biometrics, document checks and context-based attestation, confirms who someone is before any reset or access change happens, so no agent has to judge a voice in real time.
What does HYPR Affirm do differently from traditional help desk verification?
HYPR Affirm automates identity verification across onboarding, recovery and help desk interactions, removing the need for an agent to decide whether a caller is legitimate. The system verifies the person directly instead.
Who qualifies for the free HYPR Affirm offer through October 30?
Any hedge fund or financial services firm affected by this vishing wave, or any firm that wants to close this attack path before it becomes their own headline. Contact HYPR to get started.
Related Reading
Anton Gurov
CISO
Anton Gurov currently serves as HYPR's CISO, focusing on Security, Compliance and Operations. Anton’s industry background is in mobile payments, ad tech and cloud management, with direct experience in PCI-DSS/SOC2/ISO/GDPR/CSTAR compliance in private/hybrid and cloud-native organizations. His career contributions led to 3 successful startup exits totaling $1.1B+. Anton had exposure to NIST standards and controls while pursuing FedRAMP at VMware.
Related Content