In recent days, several of Wall Street's largest hedge funds and private equity firms have been targeted by attempted cyberattacks, according to a report from InvestmentNews. The attacks employed a tactic known as vishing, or voice phishing, where cybercriminals use phone calls to trick employees into granting system access or divulging sensitive information. This method, long favored by hackers for its effectiveness, has now reached a tipping point, according to a new report from voice security firm Mutare.
The vishing campaigns are part of a broader trend of increasingly sophisticated social engineering attacks. Cybercriminal groups like Scattered Spider, a loose-knit collective of young hackers, have successfully used this approach against a wide range of corporate victims. Now, artificial intelligence is amplifying the threat. AI can generate highly personalized scripts and even clone voices, making it harder for employees to distinguish legitimate calls from fraudulent ones.
Mutare's 2026 Voice Threat Survey, released this week, reveals that security leaders and business owners are beginning to recognize voice as a legitimate attack vector. Brian McDonald, Chief Security Officer at Mutare, noted, "Cybersecurity strategies have evolved dramatically over the past decade, but Voice Security has largely remained a blind spot." The survey indicates that AI-powered voice attacks, vishing, social engineering, call spoofing, and voice spam storms are now seen as growing cyber risks that can disrupt operations and provide initial access to enterprise networks.
McDonald emphasized that awareness training alone is no longer sufficient. "Organizations are beginning to understand that awareness training alone is no longer sufficient. A modern cybersecurity strategy must include technical controls that reduce opportunities for malicious callers to ever reach employees, executives, help desks, or contact center agents," he said. This shift in mindset is crucial as AI-driven attacks become more prevalent.
Parallel to the vishing campaigns, cybersecurity firm Huntress identified a phishing operation impersonating Bank of America. The campaign used a fraudulent domain that meticulously replicated the bank's visual identity, email formatting, and branding. Victims were persuaded to download a fake tool, which installed sophisticated malware on their computers. The malware disguised itself as "Windows Security," removed installation traces, and blocked uninstallation, leaving IT administrators with little time to intervene.
Lucy Finlay, Director of Secure Behaviour and Analytics at Redflags, commented on the campaign's sophistication. "What makes this campaign notable isn't the phishing tactic — it's how little room there is to fix things once the payload lands," she said. The attack was designed to lock out administrators, flipping the usual security priority: the highest-value moment to intervene is before the click, not after.
Finlay added that the attack succeeds through a chain of small individual decisions, such as clicking a link from an unrecognized sender or entering credentials on an unfamiliar page. Each decision is a point where a real-time nudge could be more effective than after-the-fact detection. "That's the uncomfortable takeaway here: the human layer is where this attack can be foiled, where the technical layer has been rendered almost powerless," she said.
For financial advisors and RIAs, these incidents underscore the importance of robust client verification protocols. As AI-driven voice cloning and deepfakes become more common, firms must adopt deliberate verification measures to protect client assets and sensitive information. The threat is not limited to large institutions; smaller firms are equally vulnerable.
The rise of AI-powered vishing also highlights the need for continuous employee training and the implementation of technical safeguards. While awareness training remains important, it must be complemented by tools that can detect and block malicious calls before they reach employees. As McDonald noted, voice security deserves the same strategic attention as email, endpoints, data, identity, and cloud security.
In the coming months, financial firms should expect more sophisticated attacks as cybercriminals leverage AI to enhance their methods. The key to defense lies in a multi-layered approach that combines technology, process, and human vigilance. For advisors, staying informed about these threats and implementing proactive measures will be essential to safeguarding their practices and clients.


