Artificial intelligence use in cyberattacks is on the rise, amid recent reports that major AI labs Anthropic and OpenAI have seen their models successfully execute live attacks even during internal testing. Defensive operators have voiced concern for some time that the capabilities of AI-assisted cyberattackers are outpacing the capabilities of cybersecurity professionals.

These fears were brought into sharp focus this week, following a coordinated series of attacks at some of the world’s largest financial institutions. A Wednesday report from Bloomberg detailed how hackers targeted Two Sigma Investments, Citadel, Point72 Asset Management and several private equity firms. Employees at each of these firms received voice phishing (“vishing”) calls, ostensibly from known colleagues at their firm, asking them to provide login credentials or two-factor authentication codes. The voices on the calls were in fact AI clones of their coworkers.

The security team at Point72 managed to identify the attack in progress, with initial reports suggesting that no client information was compromised. Two Sigma likewise reported no successful breaches. The third major target, Citadel, has yet to provide a public statement.

The culprit remains unknown

Following the attempted breaches, the Financial Industry Regulatory Authority (FINRA) contacted its member firms advising them to remain vigilant and collect incident reports, according to Bloomberg. Anticipating that such threats would become more commonplace in future, FINRA launched a secure reporting portal for cyber intelligence threats, aiming to facilitate cooperation between cybersecurity teams across the financial sector. This recent wave of attacks further validates the need for such coordination.

The culprit behind them is as yet unidentified; however, the modus operandi is already well documented. Reuters noted that such spoofed phone calls have been used by the Scattered Spider group, the hacking collective that has successfully breached over 100 corporate and government targets since 2021. It has not been established whether this group has any connection to the recent series of attacks.

A similar wave of vishing attacks by Silent Ransom Group hit U.S. legal firms and financial services companies throughout the first half of this year, according to an analysis published by Google’s Threat Intelligence Group. In some sophisticated instances, individuals posing as IT technicians even gained physical access to company buildings as part of the attack.

It is possible that this most recent wave of breach attempts had a similar objective: to compromise client records, private positions, or proprietary trading strategies, then hold these for ransom.

AI is making cyberattacks cheaper and easier to execute at scale

Large-scale vishing attacks previously required a team of human operators, each placing one call at a time, setting a hard cap on how many attempts they could feasibly make each day. Criminal outfits making use of these tactics have therefore often operated on a fairly large scale; so-called “scam compounds” in Myanmar and Cambodia employ tens of thousands of operators and can grow to the scale of a small town.

These limitations and overheads are now becoming more and more irrelevant with the rise of AI tools. Will Wilson, CEO and co-founder of software testing firm Antithesis, told Bloomberg that AI models have “made it possible to execute attacks at scale” by lowering the cost and time investment of each attempt. Given sufficiently powerful AI agents and hardware, a single individual could theoretically launch an attack that would previously have required hundreds of trained individuals working in tandem.

A successful breach requires just one employee to drop their guard and assist the attacker. When attackers can operate at such a scale, the odds of this happening increase significantly.