In recent months, a number of prominent hedge funds and asset managers have become targets of coordinated intrusion campaigns that looked nothing like the mass-distributed phishing emails of a decade ago.
Attackers combined synthetic voice replicas of senior executives, adversary-in-the-middle credential harvesting proxies and meticulously researched pretexts drawn from publicly available investor communications. Commercially available generative models and voice synthesis tools now allow those elements to be assembled at a fraction of the former cost and with far less specialist skill. Indeed, several firms reported that the attacks initially fooled experienced operations staff.
This trend reinforces a warning that regulators on both sides of the Atlantic have repeated for some time: because alternative investment managers process large volumes of high-value data while operating leaner information security infrastructure than large banks, they face distinctive cybersecurity risks.
How modern phishing works
Traditional email phishing relied on volume: attackers distributed thousands of generic messages in the hope that a small proportion of recipients would click a malicious link. That model has increasingly given way to targeted social engineering, in which generative models act as both author and strategist.
- Email Attacks
Spearphishing emails can now be drafted by large language models trained on a target’s public communications to reproduce tone, vocabulary and formatting with unnerving accuracy. Sources include earnings calls, LinkedIn posts, regulatory filings and conference panel transcripts. The same models can then quickly generate hundreds of individually tailored lures, each tailored to the recipient’s role, reporting line and recent activity.
Reconnaissance can also be automated: organisational charts, press releases, social media profiles and regulatory filings can be scraped and synthesised into detailed target dossiers with little human intervention. The effect is that a campaign which once required days of preparation for each target can now be put together in minutes.
- Voice and Video Attacks
The most significant shift in social engineering has been the move from text to voice and video. In a so-called vishing attack, an operative telephones a fund administrator or operations analyst while impersonating an IT helpdesk engineer, compliance officer or the firm’s chief financial officer. Commercial voice cloning tools — some of which are available through APIs that cost less than fifty dollars per month — can synthesise a convincing replica of an individual’s voice from as little as three seconds of publicly available audio, such as a podcast appearance, conference keynote or earnings call webcast.
Deepfake video remains less polished than cloned audio, but it can — and does — deceive participants in brief video calls. That vector was exploited in a widely reported 2024 incident in which an employee at a multinational was induced to authorise a $25 million transfer after a call with synthetic replicas of senior colleagues. And given that video conferencing remains a primary channel for fund managers coordinating with investors, administrators and counterparties, the attack surface is likely to expand.
- Credential theft and authentication bypass
Once thought of as a near-complete defence against credential theft, attackers have developed reliable ways to bypass multi-factor authentication (“MFA”). Three methods are now common. The first is MFA fatigue, in which the attacker repeatedly sends approval requests to the user’s phone until the user approves one by mistake or simply to stop the notifications. The second uses an adversary-in-the-middle proxy: a fake login page that relays traffic between the user and the genuine site, capturing the password and the second factor token so that the attacker can access the account as the legitimate user. The third is SIM swapping. Here, the attacker tricks a mobile provider into transferring the victim’s phone number to a device controlled by the attacker, with any security codes sent by text message then going directly to the attacker.
Why investment managers are high-value targets
Several features make alternative investment managers particularly attractive to sophisticated threat actors.
- They hold and transmit highly sensitive information, including proprietary trading strategies, material non-public information about portfolio companies and the data (both personal and non-personal) of investors. A breach may deliver both immediate financial gain and longer-term intelligence value.
- The industry operates under intense time pressure, with narrow trading windows and operations staff conditioned to act quickly on instructions from their investment colleagues and senior leadership. Social engineers exploit that urgency: a call purporting to come from a CFO who needs an immediate wire authorisation is difficult to refuse when the recipient knows that delay may cost basis points.
- Fund managers typically have leaner IT and cybersecurity teams than the banks with which they transact. A mid-sized hedge fund managing several billion dollars in assets may have a technology team comprising fewer than 10 individuals and rely heavily on outsourced providers for network monitoring and incident response.
- The alternative investment ecosystem is built on third-party interdependencies, including prime brokers, fund administrators, order management vendors and cloud infrastructure providers — each of which may offer an entry point. The risk introduced by a vendor’s own suppliers, known as fourth-party risk, is often not subject to rigorous due diligence.
Regulatory expectations for AI-enabled cyber threats
The UK regulatory framework does not prescribe controls for synthetic voice fraud or AI-assisted phishing, though general requirements for systems, controls and risk management are relevant to both — and it does require firms to prepare for the operational consequences of those attacks. In a series of portfolio letters (sometimes called Dear CEO letters) to the alternative investment management sector, the Financial Conduct Authority (“FCA”) has made clear that firms should identify their important business services, set tolerances for disruption and ensure they can remain within those tolerances during severe but plausible events.
For private capital firms, that analysis should now account for a targeted campaign that uses executive impersonation, credential harvesting proxies or other AI-enabled techniques to compromise critical systems or transaction processes. Those expectations are also reflected in the joint statement on frontier models and cyber resilience issued by the FCA, the Bank of England and HM Treasury earlier this year. Its emphasis on maintaining resilience as model capabilities advance is particularly relevant to the attacks described above: generative models may not create a new category of cyber risk, but they make convincing impersonation and social engineering cheaper, faster and easier to scale.
Responsibility for addressing that risk does not sit only with the information security function. Under the Senior Managers and Certification Regime, senior managers may face regulatory action, including enforcement proceedings, where weaknesses in controls over cybersecurity, payments or other critical operations fall within their areas of responsibility. The SYSC sourcebook’s general requirement for adequate systems and controls — which the FCA has indicated extends to cybersecurity and IT resilience — therefore has practical implications for how firms authenticate instructions, approve sensitive transactions, manage privileged access and train staff to respond to credible executive impersonation.
In the European Union, the Digital Operational Resilience Act ("DORA") imposes a more detailed framework on investment firms and alternative investment fund managers, including ICT risk management, incident reporting, operational resilience testing and oversight of ICT suppliers. Those obligations can be directly engaged when an AI-assisted phishing campaign leads to account compromise, disrupts an important service or exploits a weakness at a cloud, identity or communications provider. For significant entities, threat-led penetration testing should also test the human and procedural weaknesses on which sophisticated social engineering campaigns depend, rather than focusing only on technical controls.
The European Supervisory Authorities’ first annual report under DORA, published in June 2026 and about which we have previously written, illustrates the scale of the underlying exposure. The Authorities received 3,383 major ICT-related incident reports from in-scope financial entities, approximately one-third of which had a cross-border impact. Notably, the report observed that increasingly capable generative model tools should prompt organisations to strengthen cybersecurity and resilience — meaning that controls designed around generic phishing emails will no longer be enough when attackers can reproduce a senior executive’s voice, tailor a pretext to a live transaction and capture credentials through a convincing proxy site.
What firms should do now
An effective defence against phishing campaigns enhanced by generative models requires specific, layered controls. Asset managers should consider taking the following steps.
- Adopt phishing-resistant MFA in place of SMS or push notification methods that are vulnerable to the bypass techniques described above. For asset managers processing high-value transactions, hardware-bound credentials should be mandatory for users with access to trading systems, investor data or wire transfer authority.
- Implement zero trust architecture as the minimum defensible standard for fund managers operating hybrid environments with multiple cloud providers and remote employees. (Zero trust architecture assumes no implicit trust and requires continuous verification of every user and device — a strategy designed to limit the fallout when phishing compromises a single set of credentials.)
- Include simulated phishing and vishing campaigns in employee security awareness training to condition staff to recognise and report social engineering attempts in realistic conditions.
- Extend vendor due diligence to fourth-party risk, with particular attention to social engineering vulnerabilities in the vendor chain. Among other things, firms should require critical service providers, by contract, to maintain phishing-resistant authentication and social engineering awareness training and to provide timely notification of incidents affecting shared infrastructure.
- Scrutinise cyber insurance policy terms carefully, given that cover for losses arising from social engineering and wire transfer fraud — the scenarios that are most likely to arise from phishing enhanced by generative models — is frequently subject to sub-limits or specific exclusions.
Subscribe to Ropes & Gray Viewpoints by topic here.
Authors
Stay Up To Date with Ropes & Gray
Ropes & Gray attorneys provide timely analysis on legal developments, court decisions and changes in legislation and regulations.
Stay in the loop with all things Ropes & Gray, and find out more about our people, culture, initiatives and everything that’s happening.
We regularly notify our clients and contacts of significant legal developments, news, webinars and teleconferences that affect their industries.
