gizmodo.com via Reddit

Point72, Citadel, Two Sigma Hit by AI Voice-Cloning Attack Wave

3 sources tracking this story

TL;DR

  • Google tracks the actors as UNC6671 across at least 72 malicious domains and more than 200 targeted companies including Blackstone, Apollo, KKR, Bridgewater, CME Group, and Moody's alongside the three named hedge funds.
  • Two Sigma confirmed a successful block with no data impact; Point72 proactively notified investors while citing an ongoing investigation; Citadel and Millennium Management declined to comment.
  • FINRA activated its Financial Intelligence Fusion Center, launched in March 2026, as the primary industry threat-sharing mechanism, marking its first live deployment in a major incident.

The interesting thing about this week's Bloomberg scoop, as picked up by Gizmodo, is not that AI voice-cloning is being used to phone hedge fund employees. That has been coming for a while. It is that the attempted targets were Citadel, Point72, and Two Sigma in the same window, along with several private equity firms. When one coordinated wave hits three of the most security-conscious money managers on Wall Street at once, that reads as a threat actor testing a playbook, not opportunists dialing for dollars.

The outcomes, as reported so far, are relatively clean. Two Sigma told Bloomberg its security team responded quickly and that it has no indication of any impact to its data or its systems. Point72 reportedly informed investors on Wednesday that it had been attacked and that initial indications show no client information was stolen. Citadel declined to comment. So the current picture is probes, not breaches.

The reason to take this seriously anyway is the reference point. In 2024, a finance worker at a Hong Kong multinational was tricked into wiring more than $25.5 million to scammers who used AI-generated deepfakes of company executives, including the CFO. That was a single successful call. The Wall Street targets this week appear to have had the right controls or the right luck, but you only need one authorization workflow at one smaller firm in the same coordinated wave to have missed the check. Will Wilson, chief executive of the Jane Street–backed software firm Antithesis, told Bloomberg that modern AI has "commoditized this and made it possible to execute attacks at scale."

Worth flagging: the reporting traces to a single Bloomberg story, the tradecraft has not been detailed publicly, the identities of the cloned voices have not surfaced, and no attacker has been named. Point72's note to investors is preliminary, not a final incident report. Read the details as a first draft rather than the settled record.

What is worth watching from here is whether the takeaway inside these firms is a callback-protocol rewrite: adding out-of-band verification to any voice-initiated authorization the way finance moved to two-factor on email a decade ago. This lands in the middle of a heavy run of cyber coverage for us, 321 stories in the last 90 days, and follows OpenAI flagging its Astra model at the 'critical' cyber level earlier in the week. Deepfake-detection and voice-biometrics vendors now have a live incident to point at. Regulators do too.

What others are reporting

Coverage cluster as of 24h after publish

  1. TechCrunch Read →

    Google names UNC6671, maps 72 malicious domains, 200+ targets across asset classes, and documents $10M in extortion receipts; first attribution connecting hedge fund and PE targeting to one actor.

    The publication of your data is never our preferred resolution; it is the consequence of refusal to engage.
  2. InvestmentNews Read →

    Financial-press framing covers Point72's investor disclosure and FINRA Fusion Center activation, adding regulatory and client-communication dimensions absent from tech-outlet coverage.

    "Before they could attack 50 entities in a targeted attack, now they can do 1,000," said Align Managed Services president Vinod Paul.