AI-Powered Vishing Targets Top Hedge Funds – Beyond Rogue AI

AI-Powered Vishing Targets Top Hedge Funds - Beyond Rogue AI

I picked up the phone and heard a voice I knew—cadence, jokes, the exact cadence of a colleague. For a beat I believed it, then the voice asked for a wire and the room emptied. If hedge funds with multi-million-dollar defenses can be baited, you should be worried too.

I’ve been tracking AI abuse for years, and the Bloomberg report that named Citadel, Two Sigma and Point72 as recent targets of vishing—AI-driven voice phishing—was a sharp reminder: the threat isn’t a Hollywood fantasy, it’s a fast-moving tradecraft. You’ll want to know how these attacks work, why they’re suddenly everywhere, and what you can actually do about them.

Citadel, Two Sigma and Point72 were named in a wave of attempted voice-based intrusions.

According to Bloomberg, teams at several high-profile hedge funds and private equity firms were targeted by calls that used AI to mimic real humans. Two Sigma says it intercepted the attempt before any systems were touched; Citadel declined to comment to reporters.

Attackers are using AI to lower the cost and raise the scale of social-engineering. The wave aimed not to break cryptography but to trick humans—front-desk operators, finance staff, executives—into handing over access.

What is vishing?

Vishing is phone-based social engineering: a scammer calls and persuades someone to transfer money, reveal credentials, or bypass a process. With AI in the loop, the call sounds authentic—tone, rhythm, even short verbal tics are replicated. I call it the confidence trick with a digital voice.

A 2024 case in Hong Kong showed how costly a single convincer can be.

An employee at a multinational’s Hong Kong office wired more than $25.5 million (€23.5 million) after scammers used AI-generated voices that imitated company leaders, including the CFO. That loss was not a technical failure so much as a human trust failure amplified by realistic audio.

Last summer someone recreated the voice of then-Secretary of State Marco Rubio and targeted diplomats and officials. OpenAI also flagged campaigns that used ChatGPT to mass-produce inflammatory posts aimed at stoking opposition to data centers. Scams now operate at political scale and financial scale at once.

How do AI voice scams work?

Attackers stitch together audio models, public clips and a short sample to make a convincing utterance. Models like OpenAI’s GPT-Live-1 are trained to smooth speech and timing so calls don’t sound robotic. The result is a social-engineering tool that behaves like a counterfeit key—small, precise, and designed to fit an existing lock.

AI labs build smoother voices while defenders scramble to add friction.

OpenAI and others advertise voice models as companions and accessibility tools; the same tech that comforts a lonely user can also be repurposed into a convincing scam. OpenAI’s safeguards now forbid impersonation of named individuals, but enforcement is messy and lagging.

Market pressure—investors and users demanding more natural interaction—has pushed companies to optimize for believability. Regulation is thin, incentives favor speed, and many orgs still rely on human judgment as the last line of defense.

How can firms protect against vishing?

If you run security or treasury, you need layered controls: mandatory callback numbers, out-of-band confirmations using pre-agreed channels, blunter limits on wire size, and transaction quarantines. Train staff on AI-specific red flags and run simulated attacks; your defenses must treat voice as a high-risk auth vector.

On the vendor side, platforms such as OpenAI, Microsoft and others must harden identity checks and give customers clearer provenance tools. Regulators and prosecutors should treat synthetic impersonation as a distinct attack vector with real penalties.

We’re watching a small number of bad actors test a new toolkit on financial powerhouses; if the tests succeed, the playbook spreads. Scams like these are not a software bug you can patch overnight, they are a social problem dressed in code and they will spread like mold in a damp house unless incentives change.

I’ll keep tracking the headlines and the technical signals. You should ask your security team one blunt question right now: if a voice that sounds exactly like your CFO asks for an urgent wire, how will you prove it’s real?