A recent AI-powered voice-cloning campaign targeting leading hedge funds, including Point72, Two Sigma, and Citadel, underscores how rapidly identity-based attacks are evolving. Rather than exploiting technical vulnerabilities, attackers are increasingly targeting people and business processes, using convincing AI-generated voices to impersonate trusted executives and manipulate IT help desks into granting access.
The incidents reflect a broader shift in cybercrime: attackers are focused on exploiting weaknesses in identity verification.
According to Bojan Simic, CEO and co-founder of HYPR and a board member of the FIDO Alliance, organizations should view these attacks as evidence that traditional methods of verifying identity are no longer sufficient.
“The reported AI voice attacks targeting major Wall Street firms expose a fundamental flaw in enterprise security: organizations still rely on humans to verify digital identities using their ears and intuition. Today, attackers need only seconds of publicly available audio to clone an executive’s voice and manipulate helpdesks into approving password resets, privileged access, or financial transactions. In 2026, automated AI agents are leaking more credentials than human error ever did, shifting identity risk from human-scale mistakes to industrial-scale machine automation.”
Identity, Not Deepfake Detection, Is the Core Challenge
As generative AI tools continue to improve, the distinction between authentic and synthetic audio is becoming increasingly difficult for human listeners to detect. Security experts argue that expecting employees to identify sophisticated voice clones during live interactions is no longer a realistic defense strategy.
“The industry needs to start recognizing deepfakes as a true identity problem,” Simic says. “Sound and video are no longer trustworthy, and asking employees to distinguish real from fake is a losing battle. If your security policy depends on a human deciding whether a voice on the phone is authentic, you’re setting them—and your organization’s security posture—up for failure.”
This represents a significant architectural challenge for organizations that continue to rely on help desk verification procedures based on voice recognition, personal familiarity, or knowledge-based authentication. As AI-generated impersonation becomes more accessible and scalable, those controls become increasingly vulnerable to social engineering.
Moving Beyond Human Judgment
Security leaders have spent years training employees to recognize phishing emails and suspicious links. AI-generated voice attacks suggest that similar awareness campaigns alone will not be enough.
Instead, experts recommend redesigning high-risk workflows so that critical actions are based on cryptographic proof of identity rather than subjective human judgment.
“The answer is to eliminate human guesswork from high-risk workflows and replace subjective trust with continuous, deterministic cryptographic proof of identity,” Simic explains. “High-risk actions like password resets, account recovery and privilege escalation should require phishing-resistant, device-bound authentication—not just recognition of a familiar voice. The organizations that embrace deterministic identity assurance will render AI impersonation attacks ineffective.”
A Growing Enterprise Risk
The attacks against major financial firms illustrate how AI is reshaping identity threats across every industry. As publicly available audio from earnings calls, interviews, webinars, and podcasts becomes abundant, attackers have endless material for creating convincing executive impersonations.
For security teams, the lesson is that organizations should adopt phishing-resistant authentication methods and modern identity assurance architectures that remove subjective decision-making from critical security workflows. As AI-generated impersonation becomes more sophisticated, the organizations that treat deepfakes as an identity security challenge, rather than simply a media manipulation problem, will be better positioned to defend against the next generation of social engineering attacks.
Click Here For The Original Source.
