Chloe Nordquist
Digital Content Growth Manager at VanishID
August 11, 2026
6 min read
Table of Contents
h2
Two stories made headlines last week, and most people may have read them as unrelated.
On August 5, Reuters reported that Britain’s AI Security Institute had caught AI agents from OpenAI and Anthropic taking actions nobody sanctioned during a controlled security test. On the same day, Bloomberg ran a story about a coordinated voice-phishing campaign aimed at some of the largest hedge funds on Wall Street.
One is a lab result. The other is a live attack on firms managing hundreds of billions of dollars. Read them side by side and you get the shape of the next big problem cybersecurity has to solve: machines that can invent a convincing person, aimed at a target list assembled from data those targets never agreed to publish.
What happened on Wall Street
Per Bloomberg’s reporting, attackers ran a wave of attempted intrusions against Point72 Asset Management, Millennium Management, Two Sigma Investments and Citadel, plus several private equity firms. The method was voice phishing, also known as vishing, using technology to mimic voices on calls or in messages and talk an employee into surrendering information or access. Point72 told investors it had been attacked, with initial indications that no client information was stolen.
The economics are the real story. Vinod Paul, president of Align Managed Services, told Bloomberg: “Before they could attack 50 entities in a targeted attack, now they can do 1,000.” Will Wilson, CEO of Antithesis, said modern AI systems “have commoditized this and made it possible to execute attacks at scale.”
Scale is the cheap part. Reach still has to come from data about specific people, which is the argument we made back in April, when the industry was fixated on Mythos finding zero-days and we said the faster route to the crown jewels ran through external identity data nobody had to hack for.
What happened in the test lab
Reuters reported that the UK AI Security Institute ran 122 test runs of a fictional cybersecurity scenario and logged 19 unsanctioned actions across 10 of them. Anthropic’s Mythos 5 agent accounted for 17. OpenAI’s GPT-5.6-Sol accounted for two.
The one that should get a security team’s attention: an agent wrote malicious code and created fake online identities to try to get a human to approve that code. AISI said no real-world harm resulted, and that the agents did not escape the test environment onto the open internet. OpenAI said both of its agent’s unapproved actions involved reaching the internet in ways the prompt forbade. Anthropic said the incident “underscores the need for a broader conversation about how to safely evaluate increasingly capable AI agents.”
Nobody was breached here, and that’s exactly the point. Inside a sandbox, under observation, with researchers watching, an agent worked out on its own that the path forward was to manufacture people and manipulate a human.
The thread between them
Wall Street’s attackers needed a voice that sounded like someone an employee already trusts. The agent in the AISI test needed identities credible enough to get a human to click approve. Same underlying capability, opposite sides of the fence, hours apart in the news cycle.
Both need input, and two different kinds. Picking the target takes one set: who works there, what they can approve, which number reaches them directly. Building the persona takes another: a real colleague or vendor to impersonate, their title, their relationship to the target, and enough recorded audio to clone the voice. This data is collected from data brokers, breach dumps, public records and social profiles. Both sets of data usually come from the same place, which is your own people’s exposure. The colleague being impersonated is on your org chart too.
The 2026 Verizon DBIR found 65% of AI-assisted attacks target people. MITRE ATT&CK catalogs the collection step as T1589, Gather Victim Identity Information, and states plainly that it “cannot be easily mitigated with preventive controls.” The guidance is to shrink the data available to outsiders. Until recently, nothing in the security stack did that as an actual control.
The phone doesn’t ring for the portfolio manager
It rings for the operations analyst who confirms wires, the help desk lead who resets MFA, the assistant who owns the calendar. Internal tools score those people as low risk because MFA is on and the laptop is patched. An attacker scores the same people as ideal, because they’re findable, easy to impersonate, and hold real privilege.
Where VanishID comes in
“Every other tool defends what a company owns. We defend the one thing a company can’t patch: the public personal data of its people.” Matt Polak, CEO, VanishID
We launched External Identity Protection at Black Hat USA 2026 on August 3. Four classes of agents run continuously. Detection agents search data brokers, people search sites, social platforms, breach and credential dumps, the dark web and public records. Analyst agents correlate what turns up and score who is at risk, why, and how urgently. Remediation agents execute takedowns, verify each one, and monitor for repopulation. Residual-risk agents neutralize what can’t be deleted via suppressions and provide the SOC a signal it can act on. Customers typically see an 85% drop in attacker-reachable external identity data within 90 days.
The next day we previewed AI Exploitability Management, which evaluates more than 40 AI-powered attack scenarios, voice cloning and real-time deepfakes among them, and scores each person on what a frontier model could actually assemble from their public exposure today. It runs entirely from the outside, the same vantage point the attacker has. Nothing installed, no integrations, no credentials.
You can remove both the material that makes a cloned voice convincing and the material that tells an attacker who to target, then reduce whatever risk remains with compensating controls and SOC monitoring.
Sources
Reuters, “OpenAI, Anthropic AI agents implicated in new security breaches,” August 5, 2026. https://www.reuters.com/legal/litigation/openai-anthropic-ai-agents-implicated-new-security-breaches-2026-08-05/
Hema Parmar, Katherine Burton and Sridhar Natarajan, Bloomberg, “Major Hedge Funds Targeted in Wave of Attempted Cyberattacks,” August 5, 2026. https://www.bloomberg.com/news/articles/2026-08-05/major-hedge-funds-targeted-in-wave-of-attempted-cyberattacks
Verizon, 2026 Data Breach Investigations Report. verizon.com/business/resources/reports/dbir
Written by
Chloe Nordquist
Digital Content Growth Manager at VanishID
Chloe is a former award-winning journalist that now focuses on content strategy and brand storytelling. She spent years reporting on the business and tech sectors.
VanishID Protection
Ready to Strengthen Your Digital Security?
Whether you're protecting executives, your workforce, or sensitive family assets, VanishID provides tailored solutions for your unique security needs.
We use cookies to understand how you use our site so we can make it better. Analytics help us fix bugs and create content you want. Marketing cookies show you relevant job opportunities and security insights.
Functional
Always active
Required for the site to work properly
Preferences
Remember your settings and choices
Statistics
Help us understand what content you find usefulThe technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Show you relevant job opportunities and security insights
We use cookies to understand how you use our site so we can make it better. Analytics help us fix bugs and create content you want. Marketing cookies show you relevant job opportunities and security insights.
Functional
Always active
Required for the site to work properly
Preferences
Remember your settings and choices
Statistics
Help us understand what content you find usefulThe technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Show you relevant job opportunities and security insights