Kasey Cromer, Netlok | September 8, 2026
Executive Summary
Wall Street has always been a target. But the nature of the threat has fundamentally changed. In August 2026, a coordinated wave of AI-powered voice phishing attacks hit several of the largest hedge funds and asset managers in the United States, including Two Sigma Investments and Point72 Asset Management. Attackers used AI voice cloning to impersonate trusted executives and colleagues, pressuring employees into surrendering login credentials or granting system access. Two Sigma confirmed it detected and stopped the attempted breach with no impact to its data or systems. Point72 told investors its initial review found no client information had been stolen.
These incidents are not isolated. Mandiant’s M-Trends 2026 report, drawn from more than 500,000 hours of incident response investigations in 2025, found that voice phishing surged to 11% of all confirmed entry points, making it the second most common way attackers first get in after software exploits at 32%. Email phishing declined to just 6%. The calls are outperforming the clicks.
The strategic question is no longer whether voice phishing is a real threat. The August 2026 incidents settled that. The question is what an attacker can obtain when a convincing call gets through. Photolok by Netlok addresses that question at the identity layer.
Why Financial Services Firms Are the Primary Target
Financial services firms offer something no other sector can match: direct, scalable access to liquid capital, combined with time pressure that makes verification feel inconvenient. Hedge funds, asset managers, private equity firms, investment banks, and broker-dealers execute high-value transactions at speed, manage market-moving information, and operate through tightly interconnected systems, each representing a potential access point.
Mandiant’s M-Trends 2026 data shows financial services accounted for 14.6% of all incidents Mandiant investigated in 2025, the second most frequently targeted industry. The FBI’s 2025 Internet Crime Report registered more than 191,000 phishing and spoofing complaints, the most frequently reported cybercrime category for the third consecutive year, with business email compromise accounting for $3.046 billion in reported losses.
FS-ISAC’s Navigating Cyber 2025 report, drawing on intelligence from more than 5,000 financial firm members across 75 countries, identified AI-enabled fraud and impersonation attacks, including deepfakes targeting executives, as a central and growing threat to the sector. Economic instability amplifies all of this. When markets are volatile, urgent out-of-hours requests for capital reallocation or system access become routine. Attackers exploit that operational rhythm. Financial sector employees are conditioned to move quickly when authority commands it. AI voice cloning turns that conditioning into a vulnerability.
How AI Has Changed the Voice Phishing Threat
FINRA’s investor guidance, published in 2025, states that fraudsters need only three seconds of audio to create a credible-sounding voice clone. For financial executives, that source material is everywhere: earnings calls, conference presentations, media interviews, and internal videos are all publicly accessible and sufficient to build a working model. Once built, the clone can be deployed with scripts personalized using publicly available information about the target’s role, relationships, and current business context.
Federal Reserve Board Governor Michael Barr addressed this directly in an April 2025 speech at the Federal Reserve Bank of New York, warning that generative AI has given criminals the ability to replicate a person’s voice, phrase patterns, tone, and inflection from a short audio sample. He described this as the potential to “supercharge identity fraud” and stated that voice biometrics used for authentication are effectively defeated by current AI capabilities.
Voice phishing accounted for 23% of confirmed entry points in cloud-related incidents in Mandiant’s M-Trends 2026 report, making it the single most common way attackers got into cloud environments. CrowdStrike’s 2026 Threat Hunting Report documents that voice phishing increased 134% from 2024 to 2025, and the first half of 2026 has already matched the full volume of the second half of 2025. The threat is still accelerating.
The Identity Layer Is the Target
Every AI voice phishing call in the financial sector is designed around one objective. Attackers want to obtain a credential, trigger an authentication, gain a session, or reset access. The attacker may impersonate a managing director, a chief risk officer, or an IT help desk analyst. The voice and urgency vary. The end state is always the same. Convert a convincing call into account access.
Password-based authentication creates a structural vulnerability that awareness training cannot fully close. A well-constructed voice phishing call is designed to override skepticism by exploiting legitimate authority relationships. When someone who sounds exactly like the CIO calls an IT administrator to request an urgent password reset, the pressure to comply is real and the time to verify is short. If the authentication architecture leaves a reusable password in the transaction, the attacker has everything they came for.
The FINRA 2025 Annual Regulatory Oversight Report warns member firms to consider whether their cybersecurity programs address the use of generative AI to increase the credibility and severity of attacks, including deepfake audio, linking AI-enabled fraud specifically to account takeovers, fraudulent wire transfers, and unauthorized system access. The SEC Division of Examinations has similarly reinforced identity validation as a core regulatory priority, noting in its 2026 Examination Priorities that registered investment advisers and financial institutions must demonstrate resilient controls capable of mitigating sophisticated AI-generated audio and video attacks and manipulation-based fraud.
Why Traditional Defenses Are Not Enough
Financial firms have invested heavily in email security, security software on individual devices, and security awareness training. These controls matter, but they were built for a different threat model. Email filtering cannot stop a phone call. Caller ID cannot establish who is speaking. Awareness training asks employees to detect fraud by recognizing signs of deception, but AI voice cloning removes those signs. The voice is correct. The context is correct. The urgency is calibrated. There may be nothing to detect.
Mandiant’s M-Trends 2026 data shows email phishing has declined to just 6% of confirmed entry points. Attackers are moving away from channels where defenses are strongest and toward voice, cloud access, and direct human manipulation, where employee judgment is the last line of defense. Asking employees to be the final detection layer against real-time AI voice cloning in a high-pressure financial environment is not a security strategy. Employees have always been in the line of defense. What has changed is the vehicle attackers use to reach them.
The structural problem is that as long as passwords exist in the authentication workflow, a successful impersonation attempt has a clear payoff. A password can be read aloud, entered into a portal while an attacker watches, or reset through a help desk workflow. Once obtained, it can be reused or combined with further manipulation to reach higher-value systems.
How Photolok by Netlok Addresses the Gap
Photolok by Netlok operates at the identity layer and integrates with platforms such as Okta Workforce. It replaces password-based credentials specifically and does not claim to eliminate every form of credential or every security risk. Its value in a voice phishing scenario is direct: when there is no password for an employee to surrender or enter after being deceived, the attacker cannot convert a convincing phone call into account access.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker captures or records a session, they cannot use it because the encryption and device binding lock them out. A voice phishing call that ends with the employee cooperating with a credential request returns nothing of value, because even if the photos were obtained, the encryption and device binding make them unusable without the registered device and server-side access code.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired and there is nothing to capture that can be reused to break in again. For financial firms where session hijacking and help desk resets are common attack objectives, this removes a persistent category of risk.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. Duress photos are silent alarms. If an employee is pressured by someone impersonating an executive, colleague, or IT staff member into authenticating under coercion, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen, while the login appears normal to the attacker. In a financial sector environment where employees may face significant authority pressure to comply with an urgent-sounding request, this gives the organization a way to detect and respond to coerced authentication without requiring the employee to openly challenge the caller, a capability that passwords, passkeys, and biometrics do not provide.
For financial services CISOs, the strategic case is straightforward: the August 2026 incidents demonstrated that even well-resourced firms with strong security programs are targeted by AI voice phishing. The question is not whether the calls will come. It is what the attacker can obtain when one succeeds. Photolok changes that answer at the identity layer, without requiring changes to the trading platforms, portfolio systems, or core infrastructure behind the login.
The Bottom Line
The August 2026 AI voice phishing campaign against Wall Street’s largest hedge funds is a marker, not an outlier. Voice phishing is now the second most common way attackers gain entry to enterprise systems globally, making the financial sector’s combination of liquid assets, interconnected systems, authority-driven culture, and market urgency an ideal target for a threat that exploits trust.
FINRA and the SEC have both issued guidance making clear that AI-generated audio and video attacks are regulatory concerns, not just security concerns. Firms that rely solely on awareness training, email filtering, and caller verification to defend against AI voice cloning are betting that their employees can reliably detect deception that is designed to be undetectable.
The more durable defense is to remove what the attacker is calling to collect. Photolok removes passwords from the identity layer, replacing them with a credential type that cannot be handed over in a phone call or captured and reused, and gives security teams a real-time signal when someone is authenticating under duress.
The call will come. What the attacker walks away with is the question Photolok answers.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Mandiant. ‘M-Trends 2026.’ March 2026. cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
[2] FBI Internet Crime Complaint Center. ‘2025 Internet Crime Report.’ 2026. ic3.gov
[3] FS-ISAC. ‘Navigating Cyber 2025.’ May 2025. fsisac.com
[4] FINRA. ‘Protecting Your Investment Accounts From GenAI Fraud.’ 2025. finra.org
[5] FINRA. ‘2025 Annual Regulatory Oversight Report.’ January 2025. finra.org
[6] Federal Reserve Board. ‘Deepfakes and the AI Arms Race in Bank Cybersecurity.’ April 2025. federalreserve.gov
[7] CrowdStrike. ‘2026 Threat Hunting Report.’ August 2026. crowdstrike.com
[8] SEC Division of Examinations. ‘2026 Examination Priorities.’ 2026. sec.gov
[9] Public reporting on the August 2026 AI voice phishing campaign targeting Wall Street investment firms, including confirmed statements from Two Sigma and Point72.
[10] Netlok. ‘How Photolok Works.’ netlok.com
The Call That Could Move Millions: How AI Voice Fraud Came to Wall Street
Kasey Cromer, Netlok | September 8, 2026 Executive Summary Wall Street has always been a tar[...more]
Deepfakes Don’t Need Your Password. Your Employees Will Hand It Over.
Kasey Cromer, Netlok | August 24, 2026 Executive Summary Targeted impersonation is no longer[...more]
Does a non-human own your ID?
Kasey Cromer, Netlok | August 4, 2026 Executive Summary For years, enterprise security p[...more]
Critical Infrastructure Isn’t Breached. It’s Logged Into.
Kasey Cromer, Netlok | July 15, 2026 Executive Summary In 2026, the most consequential cyberattac[...more]
AI-Powered Phishing and the Speed of Attack
Kasey Cromer, Netlok | June 16, 2026 Executive Summary In 2026, phishing is no longer a numbers game[...more]
Helpdesk is the Easiest Breach in Your Organization
Kasey Cromer, Netlok | June 9, 2026 Executive Summary In 2026, the most dangerous entry point in you[...more]
Leaner Teams, Smarter Logins: Why Eliminating Passwords Is the Right Move for 2026
Kasey Cromer, Netlok | May 27, 2026 Executive Summary In 2026, security leaders are being asked to d[...more]
When anyone can be faked: Photolok as the identity layer for the AI era
Kasey Cromer, Netlok | May 13, 2026 Executive summary As we move through 2026, the corporate world i[...more]
App Overload: Why SaaS apps and AI Sprawl Are Breaking Enterprise Security
Kasey Cromer, Netlok | April 29, 2026 Executive summary In 2026, most enterprises are running more a[...more]