TL;DR: AI-cloned voice attacks against Point72, Citadel, Millennium Management and Two Sigma succeeded by pressuring help desk staff into resetting credentials and access in real time, according to HYPR and reporting cited from InvestmentNews, Bloomberg and Reuters. Human judgment is no longer a reliable final control when identity proofing still depends on a believable call.
NHIMG editorial — based on content published by HYPR: Thwarting the AI Vishing Attacks That Targeted Point72, Citadel, Two Sigma and More
By the numbers:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
Questions worth separating out
Q: How should organisations secure help desk account recovery against AI vishing?
A: They should remove identity decisions from voice conversations and require proof-based verification before any reset or re-enrollment occurs.
Q: Why do AI-cloned voices make social engineering harder to stop?
A: Because they remove the weak cues humans used to spot older scams, such as poor audio quality, odd phrasing, or obvious impersonation.
Q: What do security teams get wrong about help desk verification?
A: They often treat it as a service procedure instead of an identity control.
Practitioner guidance
- Remove voice-based trust from recovery workflows Require identity proofing that does not depend on a caller sounding legitimate.
- Treat help desk resets as privileged access events Classify account recovery, credential replacement, and authentication factor changes as high-risk identity transactions.
- Separate support velocity from security authority Do not let call-time pressure or ticket closure targets influence identity decisions.
What's in the full article
HYPR's full blog post covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of the identity proofing flow used to stop AI vishing at the help desk
- Specific workflow guidance for ServiceNow, Jira, and other ticketing environments
- HYPR's implementation framing for document checks, liveness, geolocation, and context-based attestation
- The offer terms and deployment details for affected financial services firms
👉 Read HYPR's analysis of AI vishing attacks against help desk recovery flows →
AI vishing and help desk resets: are your recovery controls enough?
Explore further
AI vishing is a human-identity problem, but the failure mode is architectural. The attacker did not need to break authentication directly because the help desk itself became the trust boundary. That means passwordless and MFA reduce exposure only if recovery and reset workflows are equally hardened. Practitioners should treat identity recovery as part of the core IAM attack surface, not as a back-office support function.
A few things that frame the scale:
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: Who is accountable when a reset or recovery call is used to steal access?
A: Accountability sits with the organisation that allowed a high-risk identity action to depend on an unverified conversation. The relevant frameworks are IAM governance, access control, and identity proofing, not just user awareness training. If the workflow can be fooled by synthetic speech, the control design is incomplete.
👉 Read our full editorial: AI vishing exposes the identity gap in help desk recovery flows