AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion Group
AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two (TL-2026-1963), also tracked as Wall Street Hedge Fund Vishing Wave, is a high-severity phishing campaign, first published 2026-08-09. It is attributed to UNC6671 with medium confidence, affects N/A (social-engineering/identity-process attack, not a software, maps to 14 MITRE ATT&CK techniques (T1020, T1071, T1087), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-1963
- Threat ID
- TL-2026-1963
- Also known as
- Wall Street Hedge Fund Vishing Wave, Point72 AI Vishing Incident, Hedge Fund AI Voice-Cloning Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-09
- Last reviewed
- 2026-08-09
- Attribution
- UNC6671
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial services, hedge funds, asset management, private equity, legal services, financial rating agencies
- Target regions
- North America, united states of america
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two
Malware and tooling: BlackFile, Citadel, Falcon, Helix, Pink, Redact
On August 5, 2026, a coordinated wave of AI voice-cloning vishing attacks targeted Point72 Asset Management, Citadel, Two Sigma Investments, and Millennium Management, with attackers impersonating IT help-desk staff and colleagues to trick employees/help-desk agents into resetting credentials and granting system access. Point72 confirmed the attack and found no client data stolen; Two Sigma said it blocked the attempt outright. Security reporting ties the TTPs and July 2026 sector-targeting pivot to UNC6671, the multi-brand data-theft extortion group behind the BlackFile/Redact/Pink/Helix/Falcon brands.
How AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two works
Beginning August 5, 2026, four of Wall Street's largest hedge funds — Point72 Asset Management, Citadel, Two Sigma Investments, and Millennium Management — along with several unnamed private-equity firms were targeted in a coordinated voice-phishing (vishing) campaign that used AI voice-cloning to impersonate trusted IT support staff and colleagues. Attackers called employees and IT help-desk agents directly (in some cases dialing personal mobile numbers rather than office lines to bypass corporate call-monitoring controls), used a cloned voice replicating a trusted colleague's or IT technician's tone and phrasing, and pressured the target into an urgent 'security migration' or 'passkey enrollment' pretext — asking the help-desk agent to reset MFA/credentials or enroll a new authentication device in real time.
Point72 notified investors it had been hit and that its initial review found no client data had been stolen, though the investigation was continuing; the firm declined further public comment. Two Sigma stated it successfully blocked the attempt with no impact to data or systems. Citadel and Millennium Management declined to comment on whether their defenses were breached. FINRA confirmed its Financial Intelligence Fusion Center (FIFC) — a near-real-time threat-intelligence-sharing portal for member firms launched March 31, 2026 — was activated and in contact with affected firms, marking the FIFC's first live operational test since launch.
While the source reporting on Point72 specifically noted 'Scattered Spider' only as a group known for similar social-engineering tactics historically (against targets such as Erie Insurance and Aflac) without confirming direct attribution, subsequent technical reporting (BleepingComputer, Google Threat Intelligence Group/Mandiant, The Hacker News) ties the TTPs and timing of this campaign to UNC6671 — a financially motivated data-theft extortion cluster that has operated under the brand names BlackFile (emerged February 2025, retired/disputed-shutdown May 11, 2026), Redact (rebrand announced June 27, 2026), and the concurrently active Pink, Helix, and Falcon brands. GTIG assesses a single core intrusion group likely drives the helpdesk-vishing and cloud-data-theft activity behind these brands, based on shared phishing-panel infrastructure, code/template reuse, and continued Bitcoin cashouts through the disputed 'shutdown' period. UNC6671's targeting shifted from manufacturing/healthcare/real-estate/technology/transportation/hospitality sectors toward private equity, hedge funds, major law firms, and financial-rating agencies starting July 2026 — directly preceding the August 5 hedge-fund wave.
UNC6671's documented kill chain: vishing calls to personal mobile devices posing as corporate IT help desk mandating urgent FIDO2 passkey enrollment or MFA changes; victims/agents directed to adversary-in-the-middle (AiTM) phishing portals on lookalike 'passkey'/'sso' domains that harvest credentials and session/MFA tokens in real time; attacker-controlled MFA devices registered on the compromised account while legitimate MFA and password-reset notification emails are deleted to evade detection; the compromised Okta/Microsoft Entra ID SSO account is then used as a single point of entry into connected SaaS platforms (Microsoft 365, Google Workspace, Salesforce and its OAuth-connected ecosystem); automated, script-driven bulk data exfiltration follows (identifiable by non-human user-agent strings hitting cloud APIs), after which the group extorts victims via brand-specific data-leak sites, with initial demands of $1-3M USD typically settling around $750K (a 50-75% reduction) in the majority of tracked cases. Between January 7 and May 12, 2026 alone, GTIG tracked ~141.65 BTC (~$10.6-10.7M USD) in ransom payments across 18 wallets tied to the BlackFile era of the operation.
MITRE ATT&CK techniques used in TL-2026-1963
Exfiltration
T1020 Automated Exfiltration; T1537 Transfer Data to Cloud Account
Command and Control
T1071 Application Layer Protocol
Discovery
T1087 Account Discovery; T1526 Cloud Service Discovery
Persistence
Credential Access
T1110 Brute Force; T1557 Adversary-in-the-Middle
Impact
lateral-movement
T1550 Use Alternate Authentication Material
defense-impairment
T1556 Modify Authentication Process
Initial Access
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Affected products and versions in AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two
- N/A (social-engineering/identity-process attack, not a software vulnerability) — Okta / Microsoft Entra ID SSO, Microsoft 365, Google Workspace, and connected SaaS/OAuth-integrated applications (e.g. Salesforce ecosystem)
Vulnerable versions: Any tenant relying on phone-verifiable or knowledge-based help-desk identity verification for MFA/credential reset
Fixed in: Tenants enforcing FIDO2/WebAuthn phishing-resistant MFA with managed-device conditional access
Remediation for AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two
Immediate actions
- Alert help-desk/IT support staff to the active pretext (urgent FIDO2 passkey enrollment or MFA-reset requests arriving via voice call, especially to personal mobile numbers) and require out-of-band, non-phone-based identity verification before any credential or MFA action
- Review Okta/Entra ID logs for 'system.multifactor.factor.setup' events preceded by authentication failures, and for MFA device enrollments/resets performed shortly after help-desk contact
- Search SaaS audit logs (SharePoint/M365 FileAccessed, Okta System Log) for high-volume file access or auth events from non-human user agents (python-requests, PowerShell, generic Go/Okta-mobile clients) or from residential-proxy/commercial-VPN source IPs inconsistent with employee baselines
- Block/flag the known UNC6671 lookalike phishing domains and proxy/exfiltration IPs listed in this record at email/web gateways and SIEM watchlists
Workarounds
- Require call-back verification to a pre-registered corporate extension (never a caller-supplied number) before any help-desk-initiated credential or MFA change
- Temporarily restrict help-desk MFA-reset authority to require secondary manager/security-team approval for financial-sector and other high-value target roles
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2 hardware security keys, platform passkeys, Windows Hello) — WebAuthn's cryptographic origin binding defeats AiTM token relay
- Enforce centralized SSO with conditional-access policies restricting authentication to corporate-managed devices/networks (MDM/EDR-enrolled, VPN/SASE), blocking unmanaged personal-device logins
- Reduce session lifetimes and require re-authentication at least once per workday plus step-up auth for sensitive actions (MFA re-enrollment, password reset, high-privilege app access)
- Remove human judgment from identity-verification decisions at the help desk — replace phone-based 'trust your gut' verification with automated, policy-enforced verification (managed-device attestation, ticket/manager callback via pre-registered numbers)
Timeline of AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two
- BlackFile extortion brand first emerges, initially targeting retail and hospitality sectors
- GTIG begins tracking BlackFile-era Bitcoin ransom payment window (through May 12, 2026), ultimately totaling ~141.65 BTC (~$10.6-10.7M USD) across 18 wallets
- AiTM phishing domains activatepasskey[.]com and enrollpasskey[.]com registered via TUCOWS, fronted by Cloudflare, targeting financial services/hospitality/energy
- Bridge domain passkeydeploy[.]com registered, later observed linking BlackFile-branded to Pink-branded victim campaigns
- BlackFile brand shutdown publicly announced; Bitcoin cashouts to BlackFile wallets continue afterward, contradicting the announced shutdown
- AiTM domains oskeysync[.]com and keysyncos[.]com registered (NICENIC/EZYDOMAIN) for Helix-branded targeting of financial services and legal sector victims
- Redact extortion brand publicly launches, describing itself as a rebrand necessitated by a compromised/rogue BlackFile affiliate
- UNC6671 targeting pivots from manufacturing/healthcare/real-estate/technology/transportation/hospitality toward private equity, hedge funds, major law firms, and financial-rating agencies
- passkeyhelpdesk[.]com registered (NICENIC, Cloudflare/Private Layer), later observed serving both Falcon- and Helix-branded victim campaigns simultaneously — evidence of shared operator infrastructure
- Coordinated AI voice-cloning vishing attacks strike Point72, Citadel, Two Sigma, and Millennium Management; Two Sigma blocks the attempt outright; FINRA's Financial Intelligence Fusion Center is activated for affected member firms in its first live operational test
- Fortune, TechTimes, InvestmentNews, TechNadu, and Benzinga report on the coordinated hedge-fund vishing wave and FINRA FIFC activation
- BleepingComputer and other outlets report the hedge-fund attack wave's TTPs and timing align with UNC6671 (BlackFile/Redact/Pink/Helix/Falcon), based on GTIG's July 2026 sector-targeting shift and documented AiTM helpdesk-vishing kill chain
- Point72 formally notifies investors of the incident, stating its initial review found no client information had been stolen, and declines further public comment; The Cyber Express publishes coverage citing possible Scattered Spider TTP overlap without confirming attribution
Sources cited for AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two
- Point72 Among Hedge Funds Hit Wall Street Cyberattacks
- Wall Street Hedge Funds Hit by Coordinated AI Vishing: FINRA Fusion Center Activated
- Thwarting the AI Vishing Attacks That Targeted Point72, Citadel, Two Sigma and More
- Point72, Citadel among hedge funds hit by AI vishing attacks
- Major hedge funds targeted in wave of attempted cyberattacks
- Hackers Target Point72, Two Sigma, Citadel in Wall Street Attacks
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
- UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
- FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats
- Scattered Spider
- Wall Street's Biggest Hedge Funds Targeted by Hackers in AI Voice Scam
- UNC6671 Vishing Gang Hijacks Microsoft 365 and Okta Accounts to Extort Financial Firms
- Cloud Threat Horizons Report H1 2026
Threats related to AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two
- UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for Extortion
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion
- O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack Enterprise Accounts
Detection coverage for TL-2026-1963
As of 2026-08-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1963 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1963
14 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.