New Gartner® report — Reality Defender is named a Market Shaper in deepfake detection, as of June 2026.

Get the report

\

Insight

\

Wall Street's Phone Calls Prove a Voice is No Longer Proof

Ben Colman

Co-Founder and CEO

In early August, several of the largest asset managers in the U.S. were reported as targets of a coordinated voice phishing campaign.

As these asset managers learned, a familiar voice on a call is no longer proof of who is on the line. This is the uncomfortable core of voice phishing financial services face in calls, meetings, and the help desk were all built to assume the opposite, and that assumption is now the attack surface where money and access move.

Point72 notified investors of the attempted intrusion, with early indications that no client information was taken. Similar attempts were reported at Two Sigma and Citadel, along with several private equity firms. Two Sigma, which manages $75 billion, said its security team responded quickly to the attempt and saw no impact to its data or systems. As of this writing, FINRA remains in contact with member firms about the attempted intrusions, in line with the intelligence-sharing portal they launched in March for managing external hacking threats.

Why AI voice phishing works on financial services

These were reported as vishing attempts, or phone-based attacks in which someone impersonates a trusted contact to talk a target into handing over credentials or granting system access. In this case, employees were reportedly called by attackers posing as colleagues they knew. Such a technique itself predates deepfakes by decades, yet what changed in recent years is the price of the impersonation. The president of Align Managed Services, which handles security for hedge funds, told Bloomberg that attackers who once hit 50 firms in a targeted campaign can now reach a thousand. He also mentioned that they can sit on a call, learn how someone speaks, and reproduce it.

Individuals cannot be trained to hear a perfectly created synthetic voice. It’s engineered to pass the exact signals people trust, like tone, cadence, and familiarity. Callbacks, code words, and awareness training all still matter, but they're still rife with faults and inefficiencies, asking a human to hear something built specifically to be unhearable.

The concept of voice as a faulty signal of trust is something financial services are still struggling to internalize even after vishing and deepfake use in social engineering attacks became commonplace years ago. Every other channel a firm runs on has been hardened over the past two decades: email got SPF and DMARC, logins got MFA and conditional access, file transfers got encryption and logging. The live call got nothing and still runs on the assumption that a familiar voice belongs to a familiar person. That assumption is now the cheapest thing in the building to exploit, with tools any consumer can access.

How firms can harden the live call

Gartner published a First Take on these attacks with a blunt premise: telephony by itself isn’t a secure business communication channel. It requires an authentication layer on top of it. The full recommendations are worth reading, but the shape of them is what matters. Map the business processes that depend on voice approvals and rank them by what an attacker could extract. Add application-level verification to the highest-risk ones, and where you can, move the process off the phone with a no-verbal-authorization policy. Pay disproportionate attention to the IT service desk, which exists to help people who cannot authenticate and is therefore the softest target in the building. Extend the insider risk tooling you already own to catch employees acting under someone else's instruction.

That is the right shape of response, but finance will keep running on voice approvals and, increasingly, on decisions made over video. Reality Defender adds a detection layer inside the channels a firm controls. RealCall analyzes audio in the contact center, while RealMeeting examines audio and video in approved Microsoft Teams meetings. Both run in real time and in-workflow, while the call is still in progress, using an ensemble of techniques rather than a single model an attacker can tune against.

Detection is a layer, not authentication. It is additive to the controls a firm already runs on the identity side, and it is never a replacement for them. What it changes is timing: a flag while the call is live and before the decision is made, rather than a forensic finding after the money moves. Adopting deepfake detection and non-verbal authorization on the channels a firm controls raises the odds of catching a call like this in the moment. It is not a guarantee, and it does not cover a call placed to a personal cellphone.

None of these funds appear to have lost data, which is the good news. At the same time, attackers reconfirmed that voice is still the unguarded channel at firms moving trillions of dollars a day. They will be back with that lesson well before the industry fully acts on it.

See RealCall and RealMeeting in action: book a demo.

Source note: Gartner, First Take: AI-Powered Voice Phishing Attacks Demand a Cybersecurity Response, Akif Khan et al., 6 August 2026.