Drawbridge Advisory Notice
Executive Summary
Our Advisory Team is monitoring reports of a series of sophisticated cyberattack attempts targeting major Wall Street investment firms, including Two Sigma, Citadel, Point72 Asset Management, and several private equity organizations (ref: Two Sigma, Citadel, Point72 Targeted in Sophisticated Wall Street Cyber Attacks – Bloomberg) . According to public reporting, attackers leveraged advanced voice phishing (vishing) techniques, potentially powered by artificial intelligence, in attempts to gain unauthorized access to corporate systems.
Threat Overview
The campaign highlights a growing trend in which threat actors use AI technologies to impersonate executives, employees, vendors, and IT personnel through highly convincing phone calls and voice messages. These attacks are designed to:
- Trick employees into revealing credentials
- Convince personnel to approve MFA requests
- Gain remote access to corporate systems
- Obtain sensitive business information
- Facilitate broader ransomware or data theft operations
- Reports indicate that modern threat actors can leverage AI tools to mimic voice characteristics, speech patterns, and communication styles at scale, dramatically increasing the effectiveness of social engineering campaigns.
Why This Matters
Historically, targeted social engineering campaigns required significant planning and resources. Today, AI-enabled tools allow attackers to conduct highly targeted attacks against hundreds or even thousands of organizations simultaneously. Advancements in AI have significantly reduced the cost and complexity of launching sophisticated social engineering campaigns.
Organizations responsible for financial assets, sensitive client information, intellectual property or critical business operations face heightened risk.
Indicators of Suspicious Activity
Organizations should treat the following as potential indicators of a vishing attempt:
- Unexpected calls claiming to be from IT, security, help desk, vendors, or executives
- Requests to disclose passwords, MFA codes, or authentication tokens
- Urgent instructions to install software or remote-access tools
- Requests to bypass established security procedures
- Calls referencing ongoing incidents that cannot be independently verified
- Unexpected requests for confidential financial, employee, or customer information
Recommended Actions
We recommend clients immediately implement or reinforce the following controls:
Executive and Employee Awareness
- Issue immediate awareness communications highlighting the risks posed by AI-enabled voice phishing.
- Train personnel to verify unusual requests through secondary communication channels.
- Reinforce “trust but verify” practices for privileged actions.
Identity and Access Management
- Require phishing-resistant MFA wherever possible.
- Disable legacy authentication protocols.
- Review privileged account access and administrative permissions.
Verification Procedures
- Establish formal callback procedures for sensitive requests.
- Require multi-person approval for high-risk transactions or access changes across all business units.
- Consider implementing verbal passphrases or other verification workflows for high-risk executive requests.
- Ensure all staff are trained on verification procedures, and reporting of incidents.
Detection and Monitoring
- Monitor authentication logs for anomalous access attempts.
- Review helpdesk tickets for unusual password reset activity.
- Increase monitoring of privileged account activity.
- Enable alerts for suspicious MFA enrollment or device registration events.
Incident Response Readiness
- Review social engineering response procedures.
- Validate contact information for incident response partners.
- Conduct tabletop exercises involving executive impersonation scenarios.
Conclusion
This activity is a timely reminder that human-targeted attacks remain one of the most effective methods of gaining initial access. Organizations should assume that AI-assisted impersonation campaigns will continue to increase in volume, realism, and sophistication.
Clients are encouraged to review social engineering defenses, strengthen verification procedures, and ensure employees understand that voice communications alone should no longer be treated as sufficient proof of identity.
Drawbridge’s Cyber Risk Intelligence help firms identify gaps in their cybersecurity program, strengthen resilience and reduce exposure to modern social engineering threats. Please contact your relationship manager to learn how Drawbridge can support you.




