AI Voice-Cloning Attacks Target Major Wall Street Firms

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Hackers used AI-powered voice-cloning technology in a wave of vishing attacks targeting major Wall Street firms, including Point72, Citadel, Millennium, and Two Sigma. The attackers impersonated executives to trick employees into revealing sensitive information. No data breaches were reported, but the incidents highlight growing AI-enabled cyber risks in the U.S. financial sector.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the use of AI-enabled voice cloning technology in vishing attacks targeting major financial firms. The AI system's involvement is in the malicious use of AI to impersonate trusted individuals and manipulate employees, which is a direct cause of the attempted cyberattacks. Even though no confirmed data breach occurred, the attacks represent realized harm attempts against critical infrastructure (financial institutions), fitting the definition of an AI Incident. The AI system's role is pivotal in enabling the sophisticated impersonation and social engineering that underpins these attacks.[AI generated]
AI principles
Robustness & digital securityTransparency & explainability

Industries
Financial and insurance servicesDigital security

Affected stakeholders
WorkersBusiness

Harm types
Economic/PropertyReputational

AI system task:
Content generation


Articles about this incident or hazard