Sophisticated voice phishing campaigns are a warning sign for Canadian advisors and wealth managers facing the same AI-powered threat landscape
Some of the world's largest hedge funds were hit with attempted cyberattacks in recent days, Reuters reported Tuesday, as cybercriminals used phone calls to try to trick employees into surrendering system access or sensitive information.
Point72 Asset Management, Two Sigma Investments, and Citadel were among the firms targeted, along with several private equity firms, according to two sources familiar with the matter who requested anonymity given the confidentiality of the situation.
Point72 notified investors Wednesday that it had faced an attack, with one source telling Reuters the firm indicated no customer information was stolen. Two Sigma, which manages approximately $75 billion in assets, said it thwarted the attempt with no indication of data or system compromise. Citadel and Point72 declined to comment; Two Sigma did not immediately respond to Reuters' request for further detail.
The attacks relied on vishing (voice phishing) in which criminals use AI tools to impersonate employees or trusted contacts over the phone, manipulating staff into granting remote access or revealing login credentials. While such attempts on major financial institutions are described by cybersecurity experts as routine, the scale and sophistication of the current wave is not.
The phone-call tactic has long been used by hackers because of its effectiveness. It has been deployed successfully by cybercriminal groups including Scattered Spider, a loose-knit group of young hackers that has accumulated a large roster of corporate victims in recent years. Now, AI is supercharging those same methods.
A new report released this week by voice security specialists at Mutare highlighted that organizations recognize that AI-powered voice attacks, vishing, social engineering, call spoofing, voice spam storms, and other forms of unwanted voice traffic represent a growing cyber risk capable of disrupting operations, compromising employees, and providing initial access into enterprise environments.
"Cybersecurity strategies have evolved dramatically over the past decade, but Voice Security has largely remained a blind spot," said Brian McDonald, Chief Security Officer at Mutare. "Our 2026 Voice Threat Survey shows that security leaders and business owners are beginning to recognize voice as a legitimate attack vector that deserves the same strategic attention as email, endpoints, data, identity, and cloud security."
The ability of AI to generate highly personalized scripts and clone voices exacerbates the potential for employees to be caught out.
"The conversation around Voice Security has fundamentally changed," McDonald added. "Organizations are beginning to understand that awareness training alone is no longer sufficient. A modern cybersecurity strategy must include technical controls that reduce opportunities for malicious callers to ever reach employees, executives, help desks, or contact center agents.
The phishing playbook
The vishing campaigns targeting hedge funds are running in parallel with equally sophisticated phishing operations across the financial sector.
Cybersecurity firm Huntress this week identified a campaign impersonating Bank of America that illustrates how precisely modern attackers can replicate a trusted brand to deceive victims.
The operation used a fraudulent domain that meticulously mimicked Bank of America's visual identity, email formatting, and branding from the initial message through to the landing page and enabling hackers to install sophisticated malware on users’ computers by persuading them to download a fake tool.
Once installed, the malware hid itself under the label "Windows Security," removed all installation traces, blocked uninstallation, and awaited attacker commands leaving IT administrators with almost no window for technical intervention.
While this was conducted on a fake website rather than BofA’s own platforms, the sophistication of the phishing operation points to the risk to financial firms and their clients. Lucy Finlay, Director of Secure Behaviour and Analytics at Redflags, said the campaign highlights a critical flaw in how organizations prioritize their defenses.
"What makes this campaign notable isn't the phishing tactic — it's how little room there is to fix things once the payload lands," she said. "Specifically designed to lock out admins working on containing the malware, this flips the usual security priority: the highest-value moment to intervene isn't after the click, it's before it."
Finlay added that the attack succeeds through a chain of small individual decisions: "clicking a link from an unrecognised sender, entering credentials on an unfamiliar page, running a downloaded .vbs file — and each one is a point where a real-time nudge is far more effective than after-the-fact detection. That's the uncomfortable takeaway here: the human layer is where this attack can be foiled, where the technical layer has been rendered almost powerless."
CIRO has published guidance for wealth management and investment firms to help them mitigate the risk of cyber incidents while the Canadian Centre for Cyber Security has additional resources for Canadian businesses and consumers.