gizmodo.com via Reddit

Point72, Citadel, Two Sigma Hit by AI Voice-Cloning Attack Wave

TL;DR

  • Bloomberg reports Citadel, Point72, and Two Sigma were targeted in a coordinated wave of AI-powered voice phishing attacks, alongside several private equity firms.
  • Two Sigma said its security team caught the attempt with no indication of impact to its data or systems; Citadel declined to comment.
  • Point72 told investors on Wednesday that initial indications show no client information was stolen in the attempted intrusion.

The interesting thing about this week's Bloomberg scoop, as picked up by Gizmodo, is not that AI voice-cloning is being used to phone hedge fund employees. That has been coming for a while. It is that the attempted targets were Citadel, Point72, and Two Sigma in the same window, along with several private equity firms. When one coordinated wave hits three of the most security-conscious money managers on Wall Street at once, that reads as a threat actor testing a playbook, not opportunists dialing for dollars.

The outcomes, as reported so far, are relatively clean. Two Sigma told Bloomberg its security team responded quickly and that it has no indication of any impact to its data or its systems. Point72 reportedly informed investors on Wednesday that it had been attacked and that initial indications show no client information was stolen. Citadel declined to comment. So the current picture is probes, not breaches.

The reason to take this seriously anyway is the reference point. In 2024, a finance worker at a Hong Kong multinational was tricked into wiring more than $25.5 million to scammers who used AI-generated deepfakes of company executives, including the CFO. That was a single successful call. The Wall Street targets this week appear to have had the right controls or the right luck, but you only need one authorization workflow at one smaller firm in the same coordinated wave to have missed the check. Will Wilson, chief executive of the Jane Street–backed software firm Antithesis, told Bloomberg that modern AI has "commoditized this and made it possible to execute attacks at scale."

The honest caveat is that the reporting is single-sourced to Bloomberg, the specific tradecraft is not public, whose voices were cloned is not public, and neither is attacker attribution. Point72's own statement to investors is preliminary, not a final incident report. Take the specifics as reported, not settled.

What is worth watching from here is whether the takeaway inside these firms is a callback-protocol rewrite: adding out-of-band verification to any voice-initiated authorization the way finance moved to two-factor on email a decade ago. Deepfake-detection and voice-biometrics vendors now have a live incident to point at. Regulators do too.