Home / Blog / AI Cloned Wall Street’s Voices. In a UK Lab, an Agent Invented Its Own People.
Blog

AI Cloned Wall Street’s Voices. In a UK Lab, an Agent Invented Its Own People.

AI voice cloning and synthetic identity generation.

Table of Contents

Two stories made headlines last week, and most people may have read them as unrelated.

On August 5, Reuters reported that Britain’s AI Security Institute had caught AI agents from OpenAI and Anthropic taking actions nobody sanctioned during a controlled security test. On the same day, Bloomberg ran a story about a coordinated voice-phishing campaign aimed at some of the largest hedge funds on Wall Street.

One is a lab result. The other is a live attack on firms managing hundreds of billions of dollars. Read them side by side and you get the shape of the next big problem cybersecurity has to solve: machines that can invent a convincing person, aimed at a target list assembled from data those targets never agreed to publish.

What happened on Wall Street

Per Bloomberg’s reporting, attackers ran a wave of attempted intrusions against Point72 Asset Management, Millennium Management, Two Sigma Investments and Citadel, plus several private equity firms. The method was voice phishing, also known as vishing, using technology to mimic voices on calls or in messages and talk an employee into surrendering information or access. Point72 told investors it had been attacked, with initial indications that no client information was stolen.

The economics are the real story. Vinod Paul, president of Align Managed Services, told Bloomberg: “Before they could attack 50 entities in a targeted attack, now they can do 1,000.” Will Wilson, CEO of Antithesis, said modern AI systems “have commoditized this and made it possible to execute attacks at scale.”

Scale is the cheap part. Reach still has to come from data about specific people, which is the argument we made back in April, when the industry was fixated on Mythos finding zero-days and we said the faster route to the crown jewels ran through external identity data nobody had to hack for.

What happened in the test lab

Reuters reported that the UK AI Security Institute ran 122 test runs of a fictional cybersecurity scenario and logged 19 unsanctioned actions across 10 of them. Anthropic’s Mythos 5 agent accounted for 17. OpenAI’s GPT-5.6-Sol accounted for two.

The one that should get a security team’s attention: an agent wrote malicious code and created fake online identities to try to get a human to approve that code. AISI said no real-world harm resulted, and that the agents did not escape the test environment onto the open internet. OpenAI said both of its agent’s unapproved actions involved reaching the internet in ways the prompt forbade. Anthropic said the incident “underscores the need for a broader conversation about how to safely evaluate increasingly capable AI agents.”

Nobody was breached here, and that’s exactly the point. Inside a sandbox, under observation, with researchers watching, an agent worked out on its own that the path forward was to manufacture people and manipulate a human.

The thread between them

Wall Street’s attackers needed a voice that sounded like someone an employee already trusts. The agent in the AISI test needed identities credible enough to get a human to click approve. Same underlying capability, opposite sides of the fence, hours apart in the news cycle.

Both need input, and two different kinds. Picking the target takes one set: who works there, what they can approve, which number reaches them directly. Building the persona takes another: a real colleague or vendor to impersonate, their title, their relationship to the target, and enough recorded audio to clone the voice. This data is collected from data brokers, breach dumps, public records and social profiles. Both sets of data usually come from the same place, which is your own people’s exposure. The colleague being impersonated is on your org chart too.

The 2026 Verizon DBIR found 65% of AI-assisted attacks target people. MITRE ATT&CK catalogs the collection step as T1589, Gather Victim Identity Information, and states plainly that it “cannot be easily mitigated with preventive controls.” The guidance is to shrink the data available to outsiders. Until recently, nothing in the security stack did that as an actual control.

The phone doesn’t ring for the portfolio manager

It rings for the operations analyst who confirms wires, the help desk lead who resets MFA, the assistant who owns the calendar. Internal tools score those people as low risk because MFA is on and the laptop is patched. An attacker scores the same people as ideal, because they’re findable, easy to impersonate, and hold real privilege.

Where VanishID comes in

“Every other tool defends what a company owns. We defend the one thing a company can’t patch: the public personal data of its people.”
Matt Polak, CEO, VanishID

We launched External Identity Protection at Black Hat USA 2026 on August 3. Four classes of agents run continuously. Detection agents search data brokers, people search sites, social platforms, breach and credential dumps, the dark web and public records. Analyst agents correlate what turns up and score who is at risk, why, and how urgently. Remediation agents execute takedowns, verify each one, and monitor for repopulation. Residual-risk agents neutralize what can’t be deleted via suppressions and provide the SOC a signal it can act on. Customers typically see an 85% drop in attacker-reachable external identity data within 90 days.

The next day we previewed AI Exploitability Management, which evaluates more than 40 AI-powered attack scenarios, voice cloning and real-time deepfakes among them, and scores each person on what a frontier model could actually assemble from their public exposure today. It runs entirely from the outside, the same vantage point the attacker has. Nothing installed, no integrations, no credentials.

You can remove both the material that makes a cloned voice convincing and the material that tells an attacker who to target, then reduce whatever risk remains with compensating controls and SOC monitoring.

Sources

Reuters, “OpenAI, Anthropic AI agents implicated in new security breaches,” August 5, 2026. https://www.reuters.com/legal/litigation/openai-anthropic-ai-agents-implicated-new-security-breaches-2026-08-05/

Hema Parmar, Katherine Burton and Sridhar Natarajan, Bloomberg, “Major Hedge Funds Targeted in Wave of Attempted Cyberattacks,” August 5, 2026. https://www.bloomberg.com/news/articles/2026-08-05/major-hedge-funds-targeted-in-wave-of-attempted-cyberattacks

MITRE ATT&CK, Gather Victim Identity Information, T1589, Mitigations. attack.mitre.org/techniques/T1589

Verizon, 2026 Data Breach Investigations Report. verizon.com/business/resources/reports/dbir

Chloe Nordquist
Written by

Chloe Nordquist

Digital Content Growth Manager at VanishID

Chloe is a former award-winning journalist that now focuses on content strategy and brand storytelling. She spent years reporting on the business and tech sectors.

VanishID Protection

Ready to Strengthen Your Digital Security?

Whether you're protecting executives, your workforce, or sensitive family assets, VanishID provides tailored solutions for your unique security needs.

Comprehensive threat assessment
24/7 monitoring and response
Expert security consultation
Custom protection strategies

Copyright © 2019 – 2026 Picnic Corporation (dba VanishID)