New Gartner® report — Reality Defender is named a Market Shaper in deepfake detection, as of June 2026.

Get the report

\

Insight

\

Wall Street's Phone Calls Are No Longer Trustworthy

Ben Colman

Co-Founder and CEO

In early August, hackers ran a coordinated voice phishing campaign against some of the largest asset managers in the U.S.

Point72 informed investors about being hacked, with early indications that no client information was taken. Similar attempts were also made on Millennium, Two Sigma, and Citadel, along with several private equity firms. Two Sigma, which manages $75 billion, said its security team responded quickly to the attempt and saw no impact to its data or systems. As of this writing, FINRA remains in contact with member firms about the breach attempts, in line with the intelligence-sharing portal they launched in March for managing external hacking threats.

How the Attachs Worked

Hackers used vishing in these instances, which are phone-based cyberattacks that impersonate trusted contacts. In these specific vishing attacks, an attacker called employees using a cloned voice of trusted colleagues and talked targets into handing over credentials or granting system access. While this technique predates deepfakes, using AI-generated voices has since made vishing attacks easier and less costly to deploy. The president of Align Managed Services, which handles security for hedge funds, told Bloomberg that attackers who once hit 50 firms in a targeted campaign can now reach a thousand, and that they can sit on a call, learn how someone speaks, and reproduce it.

That is something financial services are still struggling to learn even after deepfake use in social engineering attacks became commonplace years ago. Every channel firms use has been hardened over the past two decades: email has authentication protocols and filtering, logins have MFA and conditional access, and file transfers are logged. Yet the simple phone call never got any of this attention and still runs on the assumption that a familiar voice belongs to a familiar person. This assumption is now cheap to exploit by even less skilled attackers using technology available and accessible to consumers.

How Firms Can Prevent These Attacks

Gartner published a First Take (paywall) on these attacks with a blunt premise: telephony by itself is not a secure business communication channel and needs an authentication layer on top of it. The full recommendations are worth reading, but the shape of them is what matters. Map the business processes that depend on voice approvals and rank them by what an attacker could extract. Add application-level verification to the highest-risk ones, and where you can, move the process off the phone with a no-verbal-authorization policy. Pay disproportionate attention to the IT service desk, which exists to help people who cannot authenticate and is therefore the softest target in the building. Extend the insider risk tooling you already own to catch employees acting under someone else's instruction.

While this makes sense in theory, the finance world has always and will continue to operate on voice authorizations (and, in recent years, decisions made over video calls). Reality Defender exists as the protection layer in these familiar workflows by analyzing audio and video in real time while a call is still in progress, flagging synthetic speech in the moment. Though this is not the end-all, be-all for protection against social engineering attacks, it is the strongest signal a team can receive when relying on human interactions for approval and regular business in the age of AI deception.

In the case of the vishing attacks against these firms, adopting deepfake detection and additional non-verbal authentication/authorization would have stopped these calls from happening in a few seconds.

None of these funds appear to have lost data, which is the good news. At the same time, attackers reconfirmed that voice is still the unguarded channel at firms moving trillions of dollars a day. They will be back with that lesson well before the industry fully acts on it.


Source note: Gartner, First Take: AI-Powered Voice Phishing Attacks Demand a Cybersecurity Response, Akif Khan et al., 6 August 2026. Confirm attribution format and any required disclaimer before publishing, since this paraphrases subscription research.