← The Global Intelligence Brief

Morning Edition · Thursday, August 6, 2026Published at 1:31 AM EDT · New York

Hedge Funds Managing Hundreds of Billions Report Attempted Breaches Using Cloned Voices

Point72, Citadel, Millennium and Two Sigma were among the firms targeted, and Two Sigma said it detected the attempt with no impact to its systems.

Hedge Funds Managing Hundreds of Billions Report Attempted Breaches Using Cloned Voices

Several of the largest hedge funds on Wall Street were targeted in a coordinated campaign of attempted intrusions that used artificial intelligence to clone voices over the telephone, The Japan Times reported, citing Bloomberg. The technique, known as voice phishing, involves calling an employee while impersonating a colleague or executive and persuading that person to grant system access or hand over credentials. Point72, Citadel, Millennium and Two Sigma were among the firms approached, InvestmentNews reported.

Two Sigma, which manages about $75 billion, said it caught the attempt and found no effect on its data or systems. Citadel and Point72 did not confirm whether their systems were breached, and spokespeople for Millennium, Point72 and Citadel declined to comment to Bloomberg. Attempted breaches at Wall Street firms have risen sharply over the past year as the cost of running a convincing impersonation has fallen.

The economics explain the volume. Cloning a voice from public recordings now requires little technical skill and almost no capital, while the value of access to a large asset manager's trading and settlement systems is measured in billions. That asymmetry produces continuous attempts rather than occasional ones, and defence has to succeed every time.

A parallel case shows the same tools applied to software rather than people. The Japan Times reported that OpenAI models had been used in combination months before the breach of the machine-learning platform Hugging Face, an episode that has increased concern that advanced systems can be directed at infrastructure attacks.

Part of a tracked trend

Cheap AI Tools Industrialise Financial Fraud

The collapsing cost of convincing voice and video impersonation converts targeted financial fraud from a specialist activity into a continuous, high-volume one, forcing financial institutions into a permanent rise in security and insurance costs that compresses operating margins across the sector.

Veracity: Corroborated
80/100
If true, who benefits

Cybersecurity vendors and insurers gain from a documented wave of attempted intrusions at the most creditworthy clients in finance, and the targeted funds gain from disclosing attempts they repelled rather than losses, since an attempt described and blocked reads as competence.

The nuance

The campaign is corroborated by Bloomberg's reporting and InvestmentNews, but every account traces to a single original source, no attacker has been identified, and the article states Point72 did not confirm a breach when reporting indicates the firm told investors it was attacked and that an initial review found no client data taken.

An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.

What this means

The exposure sits with the firms holding client capital and with the insurers who underwrite their operational risk. Voice cloning defeats identity checks that rely on a person recognising a voice, which is how most fund treasury and settlement desks have historically authorised exceptions, so the response is procedural rather than technical and takes months to implement across a firm. The cost lands on operating margins through security spending and on cyber-insurance premiums, which have been rising as loss frequency increases. A single successful breach at a fund connected to the banks that provide its trading, lending and settlement services (its prime brokers) would spread beyond the fund itself, because those systems connect directly to clearing and custody at large banks.

What to watch

  • Whether any targeted firm discloses an actual breach rather than an attempt, since a confirmed loss is what moves cyber-insurance pricing across the industry.
  • Whether the Securities and Exchange Commission or other regulators issue guidance on voice-based authorisation, which would turn firm-level procedure into a compliance requirement.
  • Whether similar campaigns appear at custodian banks and clearing houses, because those institutions sit at the point where a breach affects many firms at once.

Observations to monitor, not financial advice.

3 sources

Synthesized from: The Japan Times · The Japan Times · InvestmentNews

Share this article

Comments

0

No comments yet.