Hackers are now using artificial intelligence to carry out voice phishing — or vishing — attacks against some of the largest financial institutions on Wall Street. The campaigns rely on AI-generated audio that mimics executives, vendors, or trusted contacts to trick employees into transferring funds or handing over credentials.
How the attacks work
In a typical vishing call, the attacker impersonates a senior manager or a known business partner. With generative AI, the voice can be cloned from a short sample — sometimes pulled from a public earnings call or a LinkedIn video. The target hears a familiar voice asking for an urgent wire transfer or a password reset. The technology makes the fraud harder to spot than older robocall scams.
Security teams at several Wall Street firms have reported a spike in such calls over the past quarter. Investigators say the attacks are often preceded by reconnaissance: hackers scrape social media and corporate websites to gather names, titles, and vocal samples.
Why Wall Street is a prime target
Financial firms handle high-value, time-sensitive transactions. A single successful vishing call can move millions of dollars before anyone realizes the request was fake. The same speed that makes markets efficient also makes them vulnerable. Banks and trading houses have long been targets of phishing emails, but voice-based attacks add a new layer of deception because the human ear is less trained to detect a synthetic voice than an email filter is to catch a malicious link.
Regulators have started to take notice. The Securities and Exchange Commission and the Financial Industry Regulatory Authority have both issued alerts about the rise of AI-enabled social engineering. They are urging firms to update their authentication protocols and to train employees to verify any urgent request through a separate channel.
The cost of generative AI fraud
According to industry estimates, losses from generative AI fraud could reach $40 billion by 2027. That figure includes not just vishing but also deepfake video scams, synthetic identity fraud, and automated phishing campaigns. The projection underscores how quickly the threat is growing as AI tools become cheaper and more accessible.
For now, the most effective defense remains human vigilance. Some Wall Street firms have begun requiring verbal confirmation via a second method — such as a callback to a known number — before processing any unusual request. Others are investing in AI-powered detection systems that analyze call patterns and voice anomalies in real time.
The attacks show no sign of slowing. As one cybersecurity executive put it, the technology is evolving faster than the safeguards. The next big test may come during the next earnings season, when the volume of legitimate urgent calls spikes and the line between real and fake gets even thinner.




