Wall Street hit by wave of “vishing” hack attempts

News comes as JP Morgan chief Jamie Dimon tries to form industry group

Wall Street hit by wave of “vishing” hack attempts

A wave of attempted break-ins hit some of the world's biggest hedge funds, using AI-generated voices to impersonate colleagues and talk staff into handing over access. And JPMorgan Chase chief executive Jamie Dimon has been personally calling dozens of banks, insurers, utilities and telecoms firms, trying to get them into an industry group built to get ahead of AI-driven threats. 

For anyone underwriting, brokering or reinsuring the fallout from incidents like these, the two stories are worth reading together. 

Hedge funds targeted in AI-enabled voice phishing spree 

Point72 Asset Management, the hedge fund founded by billionaire Steve Cohen, told investors on Wednesday it had been hit by hackers, though early indications suggested no client data had been taken, according to people familiar with the matter cited by Bloomberg. The same campaign also attempted to breach systems at Millennium Management, Two Sigma Investments and Citadel, along with several private equity firms, according to people familiar with the matter cited by both Bloomberg and Reuters. 

Two Sigma, which manages roughly $75 billion, said its security team caught the intrusion attempt before any systems or data were compromised. Millennium, Point72 and Citadel all declined to comment on the record. 

Attempted break-ins at major asset managers happen all the time, according to cybersecurity experts, so the target list here wasn't the notable part. The method was. Investigators pointed to "vishing," shorthand for voice phishing, where fraudsters use AI tools to clone the voice, tone and speech patterns of a real employee or executive closely enough to talk their way past a colleague on the phone. Vinod Paul, president of Align Managed Services, which advises hedge funds on cybersecurity, told Bloomberg that attackers who once needed weeks to target 50 organizations by hand can now go after a thousand, cheaply, because generative AI has made the con easy to scale. 

It's a dynamic cyber specialists have been flagging for a while. Speaking on Insurance Business's most recent cyber roundtable, Colin Fox, cyber insurance consultant at Integrity, made a similar point about AI's effect on the threat landscape more broadly: "The cyber threat landscape still remains the same, but AI will make everything happen so much quicker, much more accessible. So hackers, maybe with not a lot of experience, can maybe use AI" to pull off attacks that once took real skill to carry out. 

That's not a hedge-fund problem specifically. It's the same threat already reshaping the cyber insurance market's approach to social engineering coverage, where carriers have split since January between those explicitly excluding AI-generated deepfake fraud from standard policies and those writing it in as an affirmative grant. It also lines up with what Insurance Business has reported on the growing liability exposure tied to voice cloning, where regulatory gaps around biometric voice replication are already drawing attention from plaintiffs' lawyers. 

The tactic has a track record. Scattered Spider, the loosely affiliated group of young hackers blamed for a string of retail and insurance-sector breaches over the past two years, including the incidents at Erie Insurance and Aflac that Insurance Business reported on last year, has built a reputation on this kind of social engineering. Google's Threat Intelligence Group has also flagged a wave of similar attacks this year against law firms and other professional services firms, some reportedly involving fraudsters physically posing as IT staff to get building access, not just a phone line. 

The Financial Industry Regulatory Authority (FINRA), which oversees broker-dealers, said it has been in contact with member firms about the recent attempts. It set up a Financial Intelligence Fusion Center in March, a secure channel for sharing fraud intelligence across the industry, which suggests regulators already saw this coming as an ongoing risk rather than a one-off. 

Dimon builds a bigger tent for AI risk 

Separately, and reported exclusively by Reuters, Dimon has spent recent weeks personally calling CEOs at other large and regional banks, insurers and technology firms, inviting them to join an expanded version of the Alliance for Critical Infrastructure (ACI), a group JPMorgan helped establish alongside Mastercard and Berkshire Hathaway Energy. Outreach that began in July has reportedly reached more than 40 companies across banking, energy, water, telecoms, airlines and rail. What links those sectors is heavy reliance on technology that's becoming more AI-dependent by the month. 

According to Reuters' sources, the retooled ACI is meant to give members a shared read on how AI is being used across critical infrastructure, what risks that creates, and what safeguards are needed, while also giving the group one voice when dealing with the Trump administration on AI policy. Recent attacks on water systems in Minnesota and other states were cited as one reason for wanting faster information-sharing across sectors. The plan is to have the revamped structure running by year-end. 

Dimon has been outspoken about why he thinks this matters. He's compared giving today's most capable AI systems to the wrong people to handing out weapons, remarks made in the context of Anthropic's Mythos model, whose access briefly became a live regulatory question this summer after US export-control action prompted Anthropic to suspend and then restore it. Banks have separately been running their own tests of that model's capabilities, a process Reuters reports is distinct from the ACI initiative. 

The private-sector push runs alongside a federal one: the government's "Gold Eagle" initiative, launched in July, brings AI developers, infrastructure operators and federal agencies together to share information on vulnerabilities found by advanced AI systems and coordinate fixes. 

Why this matters for underwriters and brokers 

Neither of these stories is an insurance story on its face. But both land on the desk of anyone pricing financial-lines, cyber or tech E&O risk right now. 

The cyber insurance market has spent the past year moving from a hard market toward something closer to equilibrium. Gallagher's 2026 outlook put the global market at $16 billion to $20 billion in premium, forecasting growth toward $30 billion to $50 billion by 2030, with pricing broadly flat outside healthcare. Analysts keep attaching the same caveat to that calm: it holds as long as there's no major systemic event. Insurance Business's own coverage of the market earlier this year made the same point — premiums easing even as underlying exposure, particularly from AI-enabled attacks, keeps climbing. 

A coordinated, AI-generated vishing campaign against several of the world's largest hedge funds and asset managers looks like exactly the kind of event that could tip that balance. It also raises an underwriting question carriers are only starting to answer: does a policy's social engineering language actually respond when the "person" on the phone was a voice clone rather than a hacked email account? As Insurance Business has reported, carriers are currently split on that point, and each new incident like this one makes the split matter more. 

It's also a reminder of a coverage gap brokers in this space already watch closely. Ethan Godlieb, associate partner for cyber, tech and fintech at Consilium Insurance Brokers, made the point on Insurance Business's cyber roundtable last month that firms handling large payments shouldn't assume a standard cyber policy has them covered for exactly this kind of scam: "If you're a financial institution or anyone handling large payments, often a separate standalone crime policy with a social engineering extension is probably more appropriate, as cyber crime is often sublimited under a cyber policy." For hedge funds and asset managers moving large sums on the back of a phone call, that sublimit question is precisely what a vishing-driven loss would come down to. 

Dimon's ACI expansion points the same way. It suggests the largest buyers of cyber and property/casualty coverage no longer think they can manage AI risk quietly on their own. When the head of the country's largest bank is cold-calling peers to build a formal information-sharing structure across critical infrastructure, with an explicit goal of shaping the policy conversation in Washington, that's usually an early sign of where mandatory reporting and minimum-control requirements are headed next. Brokers advising clients in critical infrastructure sectors should expect underwriting conversations to start including a version of the question: are you part of an information-sharing framework, and can you show it? 

Both stories are still developing. Point72's investigation into what, if anything, attackers accessed was ongoing at the time of writing, and the ACI's membership drive hasn't concluded. Taken together, though, they point to the same shift the market has been talking about for months: AI is moving from being treated as a separate, priceable add-on risk to just being part of the baseline underwriting picture for cyber and critical infrastructure. 

Keep up with the latest news and events

Join our mailing list, it’s free!