On Wednesday 5 August, Bloomberg reported that several of the world's largest hedge funds – among them Citadel, Millennium Management, Two Sigma and Point72 – were targeted in a coordinated voice phishing campaign. The attackers used AI-generated voices in phone calls and voice messages to get employees to hand over login credentials or approve access to internal systems. Two Sigma says the attempt was blocked with no impact to its data or systems. Point72 notified its investors and found no indication that client data had been taken. Citadel and Millennium have not commented publicly.
The interesting part is not who was called. It is where the attack landed: not in the payment flow, but in the service desk. The inbound phone.
Below is that call broken into its parts. Not because your company is a hedge fund, but because every one of those parts exists in an ordinary service desk – and because several of them are easier to close than people think.
Second 0: the number looks right
The call arrives from a number that looks internal, or that is already in the contact list. Making that happen costs very little.
Caller ID is not a check. It is a piece of information that travels with the call, and in practice the caller chooses it. It is still the first signal the person answering responds to, and it colours everything that follows. That there are strict rules on which number a legitimate business may display helps very little against someone who does not follow rules.
What has to be true at this point: nobody in the organisation believes a number proves anything.
Second 6: the voice is familiar
Then the person speaks. It is the operations manager. Or IT support. Or a colleague from another office you have heard on a video call a handful of times.
A few seconds of public audio is enough to make a usable copy – a webinar, a podcast, a recorded voicemail greeting. Recognition is not a check. It is a feeling, and it is now trivial to produce. That the voice is a biometric characteristic has consequences well beyond fraud, but the practical consequence is this: the voice can no longer be what decides who you are talking to.
Second 25: the request is boring, and therefore believable
The attacker does not ask for a wire transfer. He says he has switched phones and cannot receive the one-time code. Or that he is at the airport and locked out of the VPN.
This is the part people underestimate. A demand for a large sum triggers suspicion. A password reset does not, because it is the single most common request a service desk handles. The attack hides inside the ordinary.
Second 40: the pressure arrives, not the question
There is always a reason it is urgent, and the reason is always reasonable: a board meeting starts in ten minutes, a client is waiting, a deadline falls today.
Time pressure is not in itself a sign of fraud. But it is the most consistent common denominator in these calls, because it is the time pressure that makes the person answering skip the step she would otherwise have taken.





