Hackers have launched an AI voice phishing campaign against several major Wall Street investment firms, including Citadel, Two Sigma, Point72 Asset Management, and Millennium Management.
The attacks use AI-generated voices to impersonate trusted people over phone calls or voice messages. Rather than relying on malware, the threat actors appear to be targeting employees directly and attempting to persuade them to share credentials, authentication codes, or access to internal systems.
Point72 alerted investors to the campaign on Wednesday. The firm said it found no evidence that attackers accessed client data.
Two Sigma says it blocked the attack
Two Sigma said its security team responded quickly after detecting an attempted vishing campaign targeting the firm and other investment managers.
The company said it had no indication that its data or systems had been affected. It also said it would continue to monitor the situation.
Citadel and Millennium Management had not publicly commented on the reported attacks at the time of publication.
The campaign reportedly also affected several private equity firms. However, the names of those businesses were not disclosed.
AI voice phishing turns trusted calls into traps
AI voice phishing, also known as vishing, uses phone calls or voice messages to manipulate people into revealing sensitive information.
Attackers can use AI tools to imitate the voice of a senior executive, a colleague, or an IT support worker. They may then ask an employee to reset a password, provide a one-time authentication code, approve a login request, or install remote-access software.
These calls can sound convincing because they exploit familiar workplace routines. A caller claiming to be from IT may create urgency by saying an account has been locked or a critical security issue requires immediate action.
The goal is usually to gain access to company systems without needing to break through technical defences directly.
Wall Street firms offer high-value targets
The targeted companies manage substantial assets for institutional and private clients.
Millennium Management oversees about $77.5 billion in assets under management, while Two Sigma manages around $75 billion. Citadel manages approximately $67.6 billion, and Point72 manages about $50.7 billion.
Access to a single employee account can provide attackers with a valuable starting point. From there, they may attempt to access internal data, financial systems, client information, or other high-value resources.
This makes employee-focused social engineering especially dangerous for investment firms, where sensitive market information and large financial transactions are common.
Investment firms now face growing cyber pressure
Investment firms have become a bigger focus for cybercriminals, according to Black Kite’s 2026 Financial Services Cybersecurity Report.
The report found that ransomware attacks across the financial sector increased by 30% in 2025. Attacks were then up another 76% during the first quarter of 2026.
Investment firms accounted for roughly 40% of finance-sector breach disclosures, which suggests attackers are increasingly shifting attention away from traditional banks.
The latest AI voice phishing attacks show why technical safeguards alone are not enough. Firms also need strong verification procedures for sensitive calls, especially when requests involve passwords, authentication codes, account changes, or payment approvals.
Employees should independently confirm unusual requests through a known contact method before taking action.


0 responses to “AI Voice Phishing Attacks Target Citadel, Two Sigma and Point72”