Wall Street’s Voice-Phishing Wave Tests the Trust Question. Will It Impact MAS Guardrails?

The attacks targeted employees, not autonomous systems. But they show why identity, authority and pre-execution controls must work together as financial institutions give AI agents more power to act.

By Sanghamitra Mandal | Aug 10, 2026
Magnific

Disclosure: Our goal is to feature products and services that we think you'll find interesting and useful. If you purchase them, Entrepreneur may get a small share of the revenue from the sale from our commerce partners.

You're reading Entrepreneur Asia Pacific, an international franchise of Entrepreneur Media.

A wave of voice-phishing attempts against some of Wall Street‘s biggest hedge funds has shown how attackers can target the human controls surrounding even the most sophisticated financial systems. Bloomberg first reported attempted attacks on firms, including Steve Cohen’s Point72, Kenneth Griffin’s Citadel and quantitative hedge fund Two SigmaThe Financial Times later reported that Millennium Management had also been targeted and provided further details of the impersonation attempts.

At one hedge fund, cybercriminals posed as the firm’s own help desk. They contacted employees in an attempt to obtain login credentials for authenticator applications, an additional security layer above usernames and passwords.

Separately, Point72 contacted law enforcement and hired outside cybersecurity experts while investigating whether its systems had been breached. The firm told investors it did not believe client information had been stolen.

Two Sigma said it had thwarted the attempt, with no indication of any impact to its data or systems. Citadel did not appear to have been breached. The FT did not report whether Millennium’s systems were breached.

Interestingly, Singapore’s financial regulator addressed a related but distinct control problem in the same week. In a written parliamentary reply for the August 5 sitting, the Monetary Authority of Singapore (MAS) said it would retain a principles-based approach to AI risk and did not commit to making the industry-developed Safeguards for Agentic Finance at Runtime, or SAFR, framework mandatory. MAS said its proposed guidelines on AI risk management would apply to all use cases, including agentic AI, and would be finalised soon.

For context, a principles-based approach sets the outcomes regulators expect firms to achieve, rather than prescribing a fixed set of technical controls for every institution or use case. That gives banks and other financial firms room to tailor safeguards to the size, complexity and risk of their AI systems as the technology evolves.

The trade-off is that consistency depends more heavily on firms’ own judgement, supervisory scrutiny and how clearly regulators define what adequate control looks like in practice.

The recent hedge-fund attacks do not directly test that framework. They involved hostile outsiders attempting to obtain access, not authorised AI agents acting outside their mandates. But both risks converge on the same question: who, or what, can be trusted to act inside a financial system.

The attackers tried to persuade employees that an unauthorised caller was a trusted internal contact making a legitimate request. In contrast, MAS’s emerging framework for agentic AI addresses the next layer: whether an AI agent proposing an action is genuinely authorised, operating within its mandate and subject to a traceable control process before it executes.

Two Tracks: Diverging or Complementary?

Singapore is treating the problems as separate tracks with different levels of regulatory force. It is further along on AI-enabled cyberdefence, where MAS has already imposed requirements on key financial institutions, than on runtime controls for institutions’ own AI agents, where it is relying on broad supervisory expectations and voluntary industry architecture.

At its annual report briefing in July, MAS said AI is making phishing more personalised and persuasive. It also warned that AI helps attackers find weaknesses in a company’s systems faster and exploit them sooner, giving defenders less time to fix a flaw before someone uses it to break in.

Since July 1, the regulator has required key financial institutions to run AI-assisted red-team exercises on critical internet-facing systems. These exercises are designed to identify potential attack paths and vulnerabilities before a real attacker could exploit them.

It also plans to issue supervisory expectations requiring those institutions to develop and submit comprehensive assessments and action plans for strengthening their defences against AI-enabled cyberthreats.

MAS and the Association of Banks in Singapore have also formed an AI-Driven Cyber and Technology Risk Taskforce, known as ABS-ACT, bringing together senior technology and cybersecurity leaders from major financial institutions to develop industry strategies and strengthen collective defence.

The less prescriptive track concerns how institutions deploy agentic AI internally. Here, MAS is relying on broad supervisory principles and SAFR’s voluntary runtime architecture rather than an agent-specific mandatory rulebook.

Traditional AI models recommend, classify or detect; AI agents can be designed to act, preparing a payment, checking a treasury instruction, reviewing advisory documents or initiating a workflow before a human intervenes. The risk is no longer whether a model gives a wrong answer, but whether a system acts too quickly, too broadly or outside the authority it was given.

What SAFR Is Built to Catch?

MAS’s 2018 ‘FEAT’ principles established fairness, ethics, accountability and transparency as the foundation for AI use in Singapore’s financial sector. Its Veritas Initiative then developed practical assessment methodologies to help financial institutions test their AI and data-analytics systems against those principles. Next, Project MindForge developed a wider AI risk-management framework covering traditional, generative and agentic AI. The proposed guidelines on AI risk management were issued for consultation in November 2025, and MAS says these will be finalised soon.

SAFR, published in July 2026 as an industry white paper under MAS’s BuildFin.ai initiative, deals with the exact moment an AI agent is about to do something, not with how it was designed or tested beforehand. The idea is simple. Before the AI system is allowed to act, a separate check confirms whether it is actually allowed to perform that specific task, and a record is kept of what it did and why. That way, a system cannot proceed merely because a proposed action appears plausible.

In payments and treasury, that might mean an AI is allowed to process routine transactions on its own, but only within pre-set transaction limits and for approved types of activity. In wealth management, it might be allowed to review documents or prepare assessments, but only within a narrow, pre-agreed task, not open-ended judgement calls. In client communications, it might draft materials, but only using content that has already been approved, not anything it generates freely.

SAFR is not a regulation and creates no compliance deadline. Its value lies in giving institutions a working model before agentic AI scales inside live systems.

Where the Model Has Yet to Be Proven

That is where the less prescriptive track faces its most open questions. SAFR‘s effectiveness will depend on how widely institutions adopt it, how fully they implement it and how its checkpoints perform once agents move into live operations.

The mandatory cybersecurity measures apply to key financial institutions. SAFR, by contrast, is voluntary across a much broader and more varied market. Its adoption may, therefore, differ among banks, insurers, asset managers, payment firms and fintechs, while proportionate supervision will depend on firms correctly judging which AI systems are material and where human approval must remain compulsory.

Singapore has built a layered regime, not an absent one. The open question is whether a principles-based, industry-led approach can produce consistently strong safeguards across a financial sector as varied as Singapore’s, or whether some risks will ultimately require binding minimum standards.

This is where external and internal risks can compound each other. Compromised employee credentials are already valuable because they grant access to systems and confidential data. They become more dangerous if they can also be used to invoke or approve AI agents authorised to initiate payments, retrieve sensitive information or set workflows in motion.

SAFR can limit that escalation by defining what an agent is authorised to do, assessing proposed actions before execution and recording consequential decisions. But it cannot replace separate security controls used to verify that the people issuing or approving those instructions are genuinely who they claim to be.

If an attacker has successfully taken over a valid account and keeps a proposed action within its authorised limits, SAFR alone may not be able to identify the social-engineering attack that came before it. That distinction is why the two regulatory tracks must work together.

Singapore’s Cyber Security Agency said about 4,800 phishing attempts were reported in 2025, down 21% from roughly 6,100 in 2024. But it also warned that AI could generate convincing voice clones and video deepfakes, as well as tools capable of bypassing multi-factor authentication.

The decline in reported attempts does not measure their sophistication, individual firms’ exposure or incidents that were never disclosed. Of course, no comparable incident involving a named Singapore financial institution has been publicly disclosed. But that absence proves neither resilience nor vulnerability on its own. Singapore’s framework, like all others, will be judged less by how it reads than by whether it can stop a compromised identity from triggering unauthorised action.

A wave of voice-phishing attempts against some of Wall Street‘s biggest hedge funds has shown how attackers can target the human controls surrounding even the most sophisticated financial systems. Bloomberg first reported attempted attacks on firms, including Steve Cohen’s Point72, Kenneth Griffin’s Citadel and quantitative hedge fund Two SigmaThe Financial Times later reported that Millennium Management had also been targeted and provided further details of the impersonation attempts.

At one hedge fund, cybercriminals posed as the firm’s own help desk. They contacted employees in an attempt to obtain login credentials for authenticator applications, an additional security layer above usernames and passwords.

Separately, Point72 contacted law enforcement and hired outside cybersecurity experts while investigating whether its systems had been breached. The firm told investors it did not believe client information had been stolen.

Sanghamitra Mandal Executive Editor

Related Content