AI telecom fraud has invaded Wall Street, and a $200 billion hedge fund has been attacked.
Wall Street giants have also been targeted by AI hackers.
Point72, Citadel and Millennium are known as the "Big Three" of Wall Street hedge funds, managing hundreds of billions of dollars in capital.
It was recently revealed that they had been breached via "AI voice cloning".
🤔Jason, my risk control system is stuck. The IT team told me to ask you to temporarily grant me permission first, could you please tell me the verification code? 😊 Oh sure, it's 0628. 😈 Thanks bro, you saved my life!
Yes, just now, Jason handed over access to his account himself.
According to reports, this group of hackers targeting Wall Street eavesdropped on phone calls to imitate the voices, tones and wording of the callers, thereby tricking employees into disclosing account information or granting system access permissions.
Vishing has evolved to an outrageous level
Vishing, short for Voice Phishing, has a more common name: voice fraud.
If voice fraud in the past was still in the cold weapon era of "bluffing, guessing, and repeated testing", the advent of AI has directly pushed it into the information age.
As we all know, early vishing was not complicated. Scammers usually impersonated bank customer service, telecom operators, police or tax authorities, used fixed scripts to create a sense of urgency, and then induced victims to disclose their bank card details, verification codes or make transfers.
In past few years, with the development of large language models and voice cloning technology, AI can be used to generate recordings in advance, which scammers then play to victims.
Later, real-time generation and cloning capabilities have also been greatly improved. The model can generate the voice of the target person instantly while receiving the conversation content, realizing almost zero-latency two-way communication.
Technology is developing so fast that many people may not even realize that based on the latest cutting-edge technology today, a voice cloning model can generate a highly similar voice with only 3 seconds of voice sample.
3 seconds, what does that mean?
This "almost" means that as long as you have posted a short video, your voice can be stolen by others.
For public figures, it goes without saying that a random clip of speech, podcast, or interview is more than enough. The entire deployment process usually only takes a few minutes, and the cost has dropped sharply to tens of dollars.
Even more, attackers do not need to build their own systems. Some hacker groups have begun to provide complete AI voice phishing services (Vishing-as-a-Service, VaaS). Customers only need to purchase the service to launch AI phone attacks targeting enterprise employees.
According to disclosures, the cost of a complete enterprise attack is about $500 to $1,000. The entire attack process has begun to be standardized and modularized like SaaS.
This kind of industrialization is also directly reflected in the number of attacks.
Since 2025, the number of global vishing attacks has increased by about 442% year-on-year. About 70% of organizations said they have experienced voice phishing attacks in the past year, and enterprises have suffered an average economic loss of about $14 million per year as a result.
Among them, the financial services industry has become the primary target of attacks, and about 44.1% of vishing incidents in 2026 are concentrated in financial institutions.
AI is becoming the new Northern Myanmar fraud hub
In 2024, a finance employee at the Hong Kong branch of the British consulting firm Arup attended a video conference.
During the meeting, the company's CFO and several colleagues asked him to execute multiple urgent remittances.
He became suspicious and requested a video call for confirmation.
In the subsequent video conference, the "CFO" and several "colleagues" he knew were all present, which made him let his guard down. He executed 15 transfers on the same day, totaling $25.6 million, to 5 Hong Kong bank accounts respectively.
No one has been arrested in this case so far, and the funds have not been recovered.
In Italy, scammers even once cloned the voice of a minister, and called many corporate executives to request urgent remittances under excuses such as "paying ransom for hostages".
Compared with voice cloning, another increasingly common type of attack directly targets the enterprise IT department.
Attackers impersonate internal employees to call technical support, lying that their accounts are locked, VPN cannot log in, or MFA devices are invalid, inducing IT personnel to reset passwords, disable multi-factor authentication, and even install remote management software.
At this stage, trying to judge the authenticity of the voice is no longer helpful, and verifying the request may become more important.
For more and more enterprises, high-risk operations involving payment, permission changes, verification codes, multi-factor authentication and other scenarios must be reconfirmed through a second communication channel, such as calling back the number in the enterprise address book, confirming via instant messenger, or requiring approval from multiple people.
The example of a senior executive at Ferrari may give us inspiration: what is more effective than verifying requests may be verifying shared memories.
He first received a series of WhatsApp messages from the CEO discussing a major confidential acquisition, and then received a call from the CEO to discuss the matter.
Image generated by AI
But the senior executive became suspicious and asked a private question that only he and the CEO knew:
Oh right, what was the name of that book you recommended to me last time? I kind of forgot.
The person on the other end hung up the call immediately.
Financial firms, law firms and medical institutions have been breached one after another
According to statistics, highly interactive voice phishing now accounts for 11% of all intrusion methods, becoming the second largest initial intrusion method after vulnerability exploitation.
Attackers are increasingly inclined to directly call the enterprise IT service desk, identity authentication departments and financial staff, bypassing the technical defense lines that enterprises have invested a lot of resources in building over the past two decades, and directly targeting people themselves.
For decades, the security guarantees in the financial industry have been relatively loose, the reason being that the skills and knowledge required to carry out attacks were extremely scarce.
It's not just the financial industry:
40% of law firms have experienced security breaches in the past year, more than half of which led to the leakage of sensitive client data, with an average breach cost of $5.08 million.
Medical systems are equally vulnerable. It is estimated that more than 40% of U.S. medical systems will face AI-powered ransomware attacks by 2026, and 60% of hospitals will experience disrupted medical services, even a sharp rise in mortality.
Security governance in the energy industry is even more laggard, with only 9% of energy organizations having conducted AI red team testing.
Between 2025 and 2026, a joint operation breached more than 760 organizations through vishing.
The confirmed victims include Google, Cisco, Adidas, Chanel, Harvard University, etc. — covering multiple industries including technology, hospitality, retail, telecommunications, aviation and higher education.
This may indicate that these attacks are not industry-specific, as long as these industries have high-value data, legacy systems and chronically insufficient security investment.
Well, but.
While the good guys are still figuring out how to respond after the bad guys get a lot more capable, the bad guys have become even more capable, and even more capable...
Indeed, the capability boundary of AI is still advancing at breakneck speed.
In January 2026, a hacker used Claude to attack a water utility system in Mexico.
In March, an AI agent of Meta replied to posts on the company's forum without authorization, eventually leading to the exposure of a large amount of internal company data and user data.
In May, a survey showed that 88% of organizations experienced at least one AI Agent security incident in the past year.
In July, OpenAI admitted that GPT-5.6 Sol once escaped the sandbox environment, connected to the Internet on its own, and carried out malicious intrusion on Hugging Face.
In August, AI Agents from OpenAI and Anthropic have been able to register accounts by themselves, forge identities, send phishing emails to real developers, and even take step-by-step actions to induce the other party to execute malicious code.
Turing Award winner, the godfather of AI Yoshua Bengio published a warning —
Following the current trajectory of AI development, autonomous cyberattacks and other high-risk AI runaway incidents will only become more frequent.
The widespread discussion about slowing down the development of large models may not be far away.
This article is from the WeChat official account "QbitAI" (ID: QbitAI), author: Cheng Qian, republished with authorization from 36Kr.