Skip to content
The Cyber Security Place

There is no gateway for the telephone

Event dated 5 August 2026 · Published 2 September 2026 · 4 sources

In early August 2026 a wave of attempted intrusions reached some of the largest money managers — reporting named Two Sigma, Citadel, Point72 and Millennium, along with private equity firms. The method was voice phishing using technology that mimics a voice on a call. Point72 told investors it had been attacked, with initial indications that no client information was taken; Two Sigma said it blocked the attempt with no impact. Those are the firms' own early accounts. The mechanism is what makes it worth reading: two decades of investment went into inspecting email, and a telephone call passes through none of it.

Almost everything written about attacks this year, on this site included, has described something that worked. This one mostly did not, and the failures are more instructive than another account of a compromise, because several organisations met the same technique and stopped it.

They are not ordinary organisations. A large fund has money, a small headcount, and an unusually direct relationship between an instruction and a transfer — which is why they were chosen, and also why they were prepared.

Why the telephone is a gap rather than a channel

Email security is an industry. Messages pass a gateway that inspects attachments, rewrites links, checks the sending domain against published policy, and appends a banner when the sender is external. None of it is perfect and all of it is inspection: something stands between the message and the person.

A call has no equivalent. There is no gateway, no attachment to detonate, no link to rewrite, no header to verify against a published record. The call arrives at a handset and the only control in the path is the judgement of whoever answers.

That gap has always existed. What changed is that exploiting it used to require a person who could impersonate convincingly in real time, in the right accent, under questioning. Synthesis removes the talent requirement, and a technique that needed a skilled performer becomes a technique that needs a sample.

What voice cloning actually removes

One check, and it is the one nearly everybody was relying on without saying so:do I recognise this person. Recognition is fast, requires no procedure, and feels like strong evidence — and it is now evidence of nothing more than that somebody obtained a recording, which for any executive who has spoken publicly is not a barrier.

The awareness advice that survives this is thinner than it looks. Telling people to be suspicious of unusual requests still helps, because urgency and unusualness remain part of the pattern. Telling them to verify that the caller is who they claim, by listening, no longer means anything.

What the firms that blocked it had

Reporting does not detail their controls, so what follows is about the class of measure that works against this rather than about any particular firm. The property that matters is a verification step that does not depend on the call: hanging up and dialling a number already held on file, or confirming through a separate channel the caller does not control.

That is the same control that defeats the majority category in cyber insurance claims —payment fraud at 58 to 60% of claims by volume — and it works here for the identical reason. It moves the decision off the channel the attacker chose, and an attacker who controls the call cannot control the number you dial back.

Its cost is friction, every time, including the many times the caller is genuine and slightly insulted. Firms where a transfer of consequence requires two people and a callback pay that cost continuously and stop this category continuously, which is the whole trade.

Why funds, and why now

A fund managing tens of billions may employ a few hundred people, and the authority to move money sits with a small, identifiable group whose names and voices are frequently public. The ratio of value to headcount is extreme, and the number of individuals who have to be convinced is small.

Reporting attributes the broader rise to AI making attacks cheaper to run at scale, which is plausible and difficult to verify from outside. What is verifiable is the shape: several of the most capable financial organisations in the world were approached in the same week by the same method, which means somebody was working through a list rather than pursuing one target.

The caveat worth keeping

Attempted, blocked, and no client information taken are early statements by the affected firms, made in the days after the event. They may hold entirely. They are also exactly the kind of assessment that this year has repeatedly shown takes months to establish — as January's hospital case demonstrated at 159 days between detection and confirmation.

The useful lesson does not depend on how those statements age. A technique that bypasses the entire apparatus built for email reached the top of the industry in one week, and the only control in its path was a procedure somebody wrote down before it happened.