Blog

Vishing Major Hedge Funds: Why AI Impersonation Targets the Help Desk

Jack Corbett4 min read

  • vishing
  • impersonation
  • financial services

On 5 August 2026, a coordinated voice phishing campaign targeted several prominent financial institutions, including Point72, Citadel, Millennium, Two Sigma and various private equity firms. Their approach was simple: attackers impersonated IT staff and internal colleagues using cloned voices, calling help desk agents and pressuring them into resetting credentials and MFA settings.

Targets were also steered to adversary-in-the-middle (AiTM) pages designed to harvest Microsoft 365 and Okta credentials and session cookies. The activity has been attributed by researchers to a threat group tracked as UNC6671. Google Threat Intelligence Group, which tracks the group, describes an extortion operation originally known as BlackFile that retired the name in May 2026 and now runs under multiple brands, including Redact, Pink, Helix and Falcon. Its recent activity concentrates on financial services, private equity and professional services, and it calls employees at victim organisations, often on their personal mobile phones.

Thankfully, most of the attempts in this campaign were reported as thwarted and no named fund has confirmed a breach. Two Sigma blocked the attempt with no indication of impact to its systems or data. Point72 told investors an initial review had found no client data taken, with the investigation continuing. Both Citadel and Millennium declined to comment.

The sector treated the campaign with immediate seriousness. FINRA activated its newly created Financial Intelligence Fusion Center in what was reported as its first real-world test, proactively contacting member firms. Similarly, the cyber insurance market is already scrutinising the attempts, assessing whether social engineering sublimits adequately respond to AI-generated voice cloning.

Why they called the help desk

The target of this campaign was the identity reset process itself, the one function in an organisation designed specifically to help someone who cannot currently prove who they are.

This campaign cleanly dismantled two common security assumptions:

  • “We have MFA.” Multi-factor authentication was not defeated by a sophisticated technical bypass. It was reset, on request, by a helpful person on a phone call. The factor was fine, the manual process around it was the vulnerability.
  • “Our security stack is comprehensive.” Every firm on that list can afford any control on the market. The gap was not in the security tools themselves, but in the process for verifying people inside the company. What was missing was a way for a help desk agent to confirm that the person on the phone was actually the colleague they claimed to be.

Think about a help desk agent taking a call at 4pm on a Friday from someone who sounds exactly like a partner needing immediate access to close a transaction. The authority and urgency on the other end of the line are the real attack.

Confirming who’s really on the call

Simply training your help desk agents to attempt to identify AI voices is no longer enough. Modern voice clones are practically indistinguishable from real human speech, particularly over compressed phone and VoIP networks. Defence relies on a process that verifies the human out-of-band before a reset occurs.

HonestID provides person-to-person verification. Before an agent resets a credential or an MFA factor, they challenge the real colleague on their registered phone through the HonestID app. A Quick Challenge takes one tap and about five seconds.

  • Device-Bound. The user’s account is bound to a single phone with hardware-backed proof of possession that signs every sensitive request. The credentials and cookies the attackers attempted to harvest are completely useless without the physical device.
  • The Separate Channel. Verification runs over HonestID’s own channel, cryptographically separate from the conversation under suspicion. A compromised mailbox, a stolen Okta session or a relayed phone call cannot reach it. This also neutralises the risk inherent in read-a-code-aloud systems, where a relayed call simply relays the code.
  • Context-Bound. The agent can specify the exact reason for the challenge, such as an MFA or password reset. The challenge carries the channel it came through, a live call or a message, along with a context category from a fixed list, one of which is account access or recovery. When the real colleague receives the prompt, they see exactly what they are being asked to approve or deny, ensuring their response is tied specifically to that action.
  • Silence is an Answer. If an impostor is on the phone claiming to be a colleague, the prompt goes to the real colleague’s device. If it was the real contact on the phone, there is no reason they couldn’t respond to the prompt. This also has the added benefit of notifying the person being impersonated straight away.

HonestID is a human-to-human verification layer that sits in front of your identity stack. It is a tool for the agent to confirm the human behind the request before they ever touch a credential or trigger a reset.