A major voice-cloning campaign has targeted help desks at hedge funds including Point72, Two Sigma, and Citadel, serving as a warning for every organization that operates a customer support center or IT help desk.
The underlying issue extends far beyond Wall Street. As generative AI makes voice impersonation increasingly accessible, contact centers are becoming one of the most attractive targets for attackers seeking to bypass security through conversation rather than code.
Help desks and customer service teams have always balanced two competing priorities: resolving issues quickly while ensuring the person requesting assistance is who they claim to be. AI-generated voice cloning is making that balance significantly harder to achieve.
According to Bojan Simic, CEO and co-founder of HYPR and a board member of the FIDO Alliance, organizations should stop expecting frontline employees to make security decisions based on what they hear.
"The reported AI voice attacks targeting major Wall Street firms expose a fundamental flaw in enterprise security: organizations still rely on humans to verify digital identities using their ears and intuition. Today, attackers need only seconds of publicly available audio to clone an executive's voice and manipulate helpdesks into approving password resets, privileged access, or financial transactions. In 2026, automated AI agents are leaking more credentials than human error ever did, shifting identity risk from human-scale mistakes to industrial-scale machine automation."
When Great Customer Service Creates Security Risk
For years, organizations have invested in reducing friction within the customer experience. Agents are trained to resolve issues efficiently, minimize escalations, and keep average handle time low.
Ironically, those same performance goals can create opportunities for sophisticated social engineering.
An attacker armed with a convincing AI-generated voice can exploit urgency, familiarity, or authority to persuade an agent to bypass established procedures. As voice synthesis becomes nearly indistinguishable from genuine speech, even experienced agents may struggle to tell the difference.
"The industry needs to start recognizing deepfakes as a true identity problem," Simic says. "Sound and video are no longer trustworthy, and asking employees to distinguish real from fake is a losing battle. If your security policy depends on a human deciding whether a voice on the phone is authentic, you're setting them—and your organization's security posture—up for failure."
Redesigning Identity Verification
Rather than investing solely in deepfake detection tools or additional employee training, organizations should evaluate whether their authentication processes rely too heavily on subjective judgment.
High-risk interactions including password resets, account recovery, changes to payment information, and privileged account requests should not depend on whether an agent believes a caller sounds legitimate.
Instead, customer service leaders should incorporate phishing-resistant, device-bound authentication into these workflows, allowing identity to be verified independently of the conversation itself.
"The answer is to eliminate human guesswork from high-risk workflows and replace subjective trust with continuous, deterministic cryptographic proof of identity," Simic explains. "High-risk actions like password resets, account recovery and privilege escalation should require phishing-resistant, device-bound authentication—not just recognition of a familiar voice. The organizations that embrace deterministic identity assurance will render AI impersonation attacks ineffective."
Supporting Agents in the AI Era
AI voice cloning is changing the role of the contact center agent. Rather than serving as the final authority on identity, agents should be supported by authentication systems that remove uncertainty from sensitive interactions.
This shift strengthens the importance of customer service. When identity verification becomes automated and cryptographically assured, agents can focus on solving customer problems instead of making high-stakes security judgments.
As AI-generated impersonation continues to improve, the most resilient customer service organizations will recognize identity assurance as a technology challenge, not a human one. Building trust into the authentication process will protect both customers and employees while preserving the fast, frictionless experiences modern organizations strive to deliver.
HYPR is on a mission to improve the lives of security-minded leaders, their employees and customers by helping organizations create trust in the identity lifecycle. HYPR provides the strongest end-to-end identity security, combining modern passwordless authentication with adaptive risk mitigation, automated identity verification and a simple, intuitive user experience. With a third-party validated ROI of 324%, HYPR easily integrates with existing identity and security tools and can be rapidly deployed at scale in the most complex environments