Back to incidents
Corporate FraudEmployees

Citadel, Point72, Two Sigma, and Millennium reportedly targeted in coordinated AI-assisted vishing campaign

Several major Wall Street firms, including Citadel, Point72 Asset Management, Two Sigma Investments, and Millennium Management, were reportedly targeted in a vishing campaign. Attackers allegedly used AI-assisted voice impersonation to mimic employees and executives over the phone, attempting to gain access or sensitive information. Two Sigma stated it detected and blocked the attempt without system impact, while Point72 reported no evidence of client information theft during its initial review.

Citadel, Point72, Two Sigma, and Millennium reportedly targeted in coordinated AI-assisted vishing campaign. Several major Wall Street firms were reportedly targeted in the same vishing campaign, with attackers allegedly impersonating employees and executives over the phone to obtain access or sensitive information. According to reporting cited by Reuters and Bloomberg, the targets included Point72 Asset Management, Two Sigma Investments, Citadel, and Millennium Management. Two Sigma said it detected and blocked the attempt without any impact to its systems, while Point72 told investors it was investigating and had not found evidence that client information was stolen during its initial review. The campaign stands out because of the reported use of AI-assisted voice impersonation. Security researchers have warned that realistic voice cloning makes traditional trust signals, such as recognizing a colleague's voice, much less reliable than they once were. FINRA has also been sharing threat intelligence through its Financial Intelligence Fusion Center as financial firms prepare for increasingly sophisticated social engineering campaigns. The article includes the confirmed statements from the affected firms, the reported attack methodology, FINRA's response, and context on recent AI-assisted vishing campaigns targeting enterprise organizations. How are organizations adapting identity verification for voice calls now that convincing AI-generated voices are becoming easier to produce?

Evidence trail

Supporting reports