How AI is enabling voice-based hacking attacks to become riskier for financial firms

How AI is enabling voice-based hacking attacks to become riskier for financial firms
Sophisticated campaigns have struck some of the country's largest money managers including hedge funds, banks.
AUG 06, 2026

Some of Wall Street's biggest hedge funds and several private equity firms were hit with attempted cyberattacks in recent days, as reported by InvestmentNews.   

The attacks used phone calls in which cybercriminals attempted to trick employees into granting system access or surrendering sensitive information a tactic known as vishing, or voice phishing, which a new report says has reached a tipping point.

The phone-call tactic has long been used by hackers because of its effectiveness. It has been deployed successfully by cybercriminal groups including Scattered Spider, a loose-knit group of young hackers that has accumulated a large roster of corporate victims in recent years. Now, AI is supercharging those same methods.

A new report released this week by voice security specialists at Mutare highlighted that organizations recognize that AI-powered voice attacks, vishing, social engineering, call spoofing, voice spam storms, and other forms of unwanted voice traffic represent a growing cyber risk capable of disrupting operations, compromising employees, and providing initial access into enterprise environments.

"Cybersecurity strategies have evolved dramatically over the past decade, but Voice Security has largely remained a blind spot," said Brian McDonald, Chief Security Officer at Mutare. "Our 2026 Voice Threat Survey shows that security leaders and business owners are beginning to recognize voice as a legitimate attack vector that deserves the same strategic attention as email, endpoints, data, identity, and cloud security."

The ability of AI to generate highly personalized scripts and clone voices exacerbates the potential for employees to be caught out.

"The conversation around Voice Security has fundamentally changed," McDonald added. "Organizations are beginning to understand that awareness training alone is no longer sufficient. A modern cybersecurity strategy must include technical controls that reduce opportunities for malicious callers to ever reach employees, executives, help desks, or contact center agents. 

The phishing playbook

The vishing campaigns targeting hedge funds are running in parallel with equally sophisticated phishing operations across the financial sector.

Cybersecurity firm Huntress this week identified a campaign impersonating Bank of America that illustrates how precisely modern attackers can replicate a trusted brand to deceive victims.

The operation used a fraudulent domain that meticulously mimicked Bank of America's visual identity, email formatting, and branding from the initial message through to the landing page and enabling hackers to install sophisticated malware on users’ computers by persuading them to download a fake tool.  

Once installed, the malware hid itself under the label "Windows Security," removed all installation traces, blocked uninstallation, and awaited attacker commands leaving IT administrators with almost no window for technical intervention.

While this was conducted on a fake website rather than BofA’s own platforms, the sophistication of the phishing operation points to the risk to financial firms and their clients. Lucy Finlay, Director of Secure Behaviour and Analytics at Redflags, said the campaign highlights a critical flaw in how organizations prioritize their defenses.

"What makes this campaign notable isn't the phishing tactic — it's how little room there is to fix things once the payload lands," she said. "Specifically designed to lock out admins working on containing the malware, this flips the usual security priority: the highest-value moment to intervene isn't after the click, it's before it."

Finlay added that the attack succeeds through a chain of small individual decisions: "clicking a link from an unrecognised sender, entering credentials on an unfamiliar page, running a downloaded .vbs file — and each one is a point where a real-time nudge is far more effective than after-the-fact detection. That's the uncomfortable takeaway here: the human layer is where this attack can be foiled, where the technical layer has been rendered almost powerless."

FINRA's Fusion Center offers a secure channel for member firms to share threat intelligence in near real-time; advisors operating under broker-dealer supervision should ask their compliance teams whether their firm is participating.

For independent advisors and planners, the broader message is that the cybersecurity threats now confronting Wall Street's largest firms are no longer confined to firms with billions under management. The same AI tools that allow hackers to target 1,000 entities at once make every firm with client data a viable mark.

Latest News

Advisor moves: LPL loses a team to Raymond James, picks up Morgan Stanley breakaways
Advisor moves: LPL loses a team to Raymond James, picks up Morgan Stanley breakaways

Two advisory teams managing nearly $1 billion in assets have moved platforms, expanding the cohort of independents.

Americans trust financial advisors most so why is there an engagement gap?
Americans trust financial advisors most so why is there an engagement gap?

New Edward Jones report reveals that internet research tops financial guidance, despite high level of confidence in professionals.

Investor accuses Pentwater of manipulating Avis stock in short squeeze
Investor accuses Pentwater of manipulating Avis stock in short squeeze

A fund allegedly built a big stake, sparked a short squeeze, then sold as shares cratered

Point72, Citadel among hedge funds hit by AI vishing attacks
Point72, Citadel among hedge funds hit by AI vishing attacks

Hackers used AI voice cloning to target Point72, Citadel, Millennium and other major money managers on Wall Street.

Financial firms tie compensation to AI proficiency, PwC survey finds
Financial firms tie compensation to AI proficiency, PwC survey finds

Recruiters Philip Waxelbaum and Louis Diamond weigh in on whether AI skills are reshaping advisor pay amid PwC's Financial Services Workforce AI Survey.

SPONSORED Direct indexing webinar targets tax-loss harvesting amid market swings

Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains

SPONSORED Who builds the income when the pension disappears?

Dan Biagini of American Equity says the steady decline of pensions, longer lifespans and a reset in interest rates are rewriting how advisors build retirement income