Invest1 distinct publisher2 min readPublished
The August 2026 calls, reported by Bloomberg and relayed in a CPA trade journal, reached people with credential reset privileges, which makes identity procedure rather than email filtering the surface under test.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The mechanism worth studying is the room the call dials into. Vishing borrows urgency or borrowed authority from a familiar voice and asks a human being with reset privileges to act [9], and it works precisely because a decade of email phishing training built awareness on the wrong channel [10]. The closest priced precedent sits at that same desk: MGM Resorts' 2023 breach, estimated at $100 million, began with a single call to IT help [6].
Gartner's split is the resource allocation story, and it is unflattering. Some 35 percent of organisations have already handled a deepfake-related incident [4], while the training attention aimed at email runs 7.3 times the attention aimed at voice [1], a 25 point gap between the firms that have met the problem and the ones teaching anyone to recognise it [2]. Every dollar routed into deepfake detection tooling is a dollar not spent making the reset desk structurally incapable of acting on a voice, which is the cheaper of the two fixes.
This is probably wrong, but I read the 40 percent per-attempt advantage [3] as a statement about target selection rather than aggregate exposure: email costs almost nothing per attempt and is fired at millions, while a cloned-voice call needs a researched target and a live operator, so the higher hit rate only converts into money when the target is worth dialling. A multi-strategy fund is worth dialling, which is presumably why three of the four named firms are described as having granted access [3]. Two Sigma stopped the attempt using whatever controls it already had in place [2], and that is the real counter-thesis here: evidence that the existing control set is closer to sufficient than the training percentages imply, though a single save is a thin base for either conclusion.
What would prove this desk wrong is specific. If the named funds disclose that independent callback verification to a number already on file was required and the callers cleared it anyway [7], the failure sits in the authentication token rather than the procedure, and the cheap fix does not hold. And if all four turn out to have lost nothing [3], then the $100 million from 2023 [6] is carrying the entire argument, which means I am pricing a nine-figure tail off one call to one help desk at a casino operator.
Ranked by verification strength, evidence, and original report placement.
In August 2026, attackers used AI-generated voice cloning to impersonate trusted colleagues at several major investment firms, including Point72, Citadel and Millennium Management, convincing staff to grant system access before anyone realised the voice was not real, according to Bloomberg's reporting as relayed by CPA Practice Advisor.
One firm, Two Sigma, caught the attempt before it caused damage.
In 2023, a single vishing call to an IT help desk was the starting point for a breach that cost MGM Resorts an estimated $100 million.
Recommended practice is to require independent callback verification before acting on any phone request involving a wire transfer, credential reset or release of financial data, with the callback going to a number already on file and never one provided by the caller.
Recommended practice includes enforcing multi-factor authentication across financial software, email and remote access tools with no exceptions granted over the phone, and requiring verified identity in help desk and password reset procedures before any change is made.
Vishing is social engineering carried out by phone, in which a caller poses as a bank representative, vendor, colleague or the firm's own IT support and uses urgency or authority to obtain credentials, transaction approval or remote access; AI voice cloning makes the calls more convincing by mimicking a real person's tone and speech patterns.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Eighty percent is a rounding error in marketing and an exception list in accounting1 distinct publisher
product
Two auctions, one week: the disclosure gap buried in Situational Awareness's $30bn July1 distinct publisher
product
Nebius funds $4.5bn of AI capacity on terms that pay lenders mostly in stock2 distinct publishers
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Everything arrives secondhand
One trade journal carries this entire story, and it reported none of it. The incident is Bloomberg's, the 40% success gap is Verizon's breach report, the training percentages are Gartner's, and not one of those primaries sits in front of us to check. What CPA Practice Advisor does supply firsthand — the definition of vishing and the control list — is the part nobody disputes.
Attack in use, defence barely started
The technique is demonstrably live: four named funds in a single month, one of them catching it, and a help desk call that preceded a nine-figure loss in 2023. The defensive side is where the number sags — on the figures relayed here, one security leader in ten trains for a cloned voice while a third of organisations have already met a deepfake. Widespread attack, thin countermeasure.
Named funds, unnamed damage
The headline names three of the most sophisticated shops on Wall Street and then quantifies nothing that happened to them; the only dollar figure in the story belongs to a casino operator three years earlier. That gap between the specificity of the names and the vagueness of the harm does the persuasive work here. The advice itself is unglamorous and sound — callbacks, MFA, identity-proofed resets — which keeps the overstatement modest rather than severe.
The fix is sold by the author
The byline belongs to the owner of a managed IT provider whose closing paragraphs advertise proactive security services to accounting and finance firms, and the recommendation to 'work with IT staff or a managed provider' sits in the middle of the checklist. Layer on two vendor research houses supplying the alarming percentages and a trade journal whose readers are the buyers, and the alignment is easy to trace — none of it hidden, all of it pointing the same way.
Direction firm, details soft
That voice cloning now works well enough to talk past trained staff is hard to doubt, and the recommended procedures stand on their own merit. Confidence drops on everything specific: what was reached inside those funds, whether the Verizon and Gartner numbers describe comparable populations, and how much of the framing is shaped by a seller of the remedy. A second, independent account would move this substantially.