The argument over whether artificial intelligence gives more leverage to attackers than to defenders has run all year in white papers and government meeting rooms. On Wednesday it landed somewhere more concrete. Bloomberg reported that hackers ran a coordinated series of attempted break-ins at some of the world's largest hedge funds, including Citadel, Point72 Asset Management and Two Sigma Investments, with several private equity firms caught in the same wave.

Two Sigma, which manages $75 billion, said its security team stopped the attempt and found no sign that data or systems were affected. Point72 told investors on Wednesday that it had been attacked, with early indications that no client information was taken and a review still running, Bloomberg reported. Citadel declined to comment on whether anyone got through. Reuters confirmed the campaign using two of its own sources later the same day.

The method was voice phishing, shortened in the security industry to "vishing." It is a phone call rather than a suspicious email. Someone rings an employee, sounds like a colleague or an internal IT technician, and talks them into surrendering a password or approving a login prompt. It works because it goes around almost everything a firm buys to keep intruders out. There is no attachment to scan and no link to block.

What changed, and what a witness said about it

Until recently, a convincing impersonation took a skilled operator working one target at a time, which capped how many people could be called before somebody noticed. That ceiling is what the industry now says has lifted. Will Wilson, chief executive of the software testing firm Antithesis, told Bloomberg that modern AI systems have "commoditized this and made it possible to execute attacks at scale." The distinction matters to anyone outside the field: the same trick that once required a talented con artist can now be run against a whole employee directory at once, and a firm's defenses have to hold on every single call.

Worth noting is what Bloomberg's account does and does not establish. It describes criminals using technology to mimic voices. It does not say that AI generated the voices in these particular calls, though a good deal of the follow-on coverage has labeled the campaign AI-powered. No group has been identified, no ransom demand has been reported, and nobody has said how many employees were called or how many picked up.

The tactic itself has a documented recent history in exactly this corner of the economy. Google's Threat Intelligence Group published findings in June on a vishing extortion campaign against US law firms and professional and financial services companies, running from January through May and attributed to a cluster it tracks as UNC3753. In some cases, Google said, people posing as IT technicians physically walked into offices. Reuters separately noted that the phone-call approach has been used to effect by Scattered Spider, the loose group of young hackers behind a string of corporate breaches, though nobody has tied that group to this week's attempts.

Regulators were already leaning in

The Financial Industry Regulatory Authority has been in touch with member firms about the attempted breaches, Bloomberg reported, citing a person with knowledge of the matter. FINRA launched a secure portal for sharing fraud and cyber threat intelligence with member firms on March 31, built specifically because the threats aimed at financial services firms were getting harder to spot alone.

The timing is awkward for Washington. On Tuesday, officials met OpenAI, Anthropic, Google and Meta to walk through a federal framework for measuring what advanced models can do in a cyberattack. That framework is designed to test models before release. It has nothing to say about criminals who already have access to voice tools and a phone.

For retail investors, there is no stock to watch here. Citadel, Point72, Two Sigma and Millennium are all private. What is exposed instead is the material these firms exist to protect: positions, counterparties, trading logic and client lists, the kind of information that is worth far more to someone who can act on it than any ransom payment. Two Sigma caught its call. The industry's problem is that this defense has to work every time, and the attackers only need one employee to be helpful.