Bloomberg, republished by Claims Journal on August 6, 2026, reported that hackers recently targeted major Wall Street money managers with attempted cyberattacks built around voice phishing, or vishing. The report named firms including Point72, Two Sigma, Citadel, Millennium Management, and several private equity firms. Two Sigma said it responded quickly to an attempted vishing campaign and had no indication that its data or systems were affected.
That is a Wall Street story, but the business lesson travels well. A convincing phone call can now become the doorway to a password reset, an MFA reset, a remote-support session, a payment change, or a sensitive file request. For New Jersey businesses, professional services firms, nonprofits, medical practices, and schools, the risk is not that every caller is fake. The risk is that too many workflows still treat a familiar voice as enough proof.
The Business Risk Is Trust Without a Second Channel
Vishing works because it attacks the normal habits of a busy organization. Someone calls with urgency. They sound like a colleague, vendor, executive, or IT support person. They ask for help. If the employee, help desk, office manager, or finance team has no firm verification process, the decision becomes personal judgment under pressure.
Google Cloud's Threat Intelligence Group described a related 2026 campaign against U.S. law firms in which attackers used voice phishing and social engineering to start conversations, push targets toward screen-sharing sessions, and persuade them to download remote monitoring and management tools. The Bloomberg report says the recent hedge-fund attempts also used vishing tactics and technology that can mimic voices, tone, and phrasing.
The practical point is simple: phone trust should not be the control. A voice can start a conversation, but it should not finish an access decision.
Where Owners Should Tighten the Process
The highest-risk requests are the ones that change access, money, or records. Those deserve a written rule before the next urgent call arrives.
- MFA resets: require a ticket, identity proof, and callback to a known number already on file.
- Password resets: do not approve them from a caller-provided number, email address, or chat account.
- Remote-support sessions: confirm the vendor, technician, ticket number, and business purpose before anyone joins a screen share.
- Payment or banking changes: require out-of-band verification and a second internal approval.
- Executive requests: treat urgency as a reason to slow the process, not speed it up.
Questions to Ask Your IT Provider or Internal Team
Owners do not need to become phone-fraud experts. They do need to know whether the business has rules that people can follow when the call feels real.
- Which requests can never be approved by phone alone?
- Do we have a callback list that employees cannot edit during the request?
- How are help-desk identity checks documented?
- Can a vendor start a remote session without a ticket we can verify?
- Who approves MFA resets for executives, finance users, and administrators?
- Are employees trained to pause when a caller asks them to bypass the normal workflow?
A Practical Next Step
Pick the five requests that would hurt most if approved for the wrong person: MFA reset, password reset, remote access, payment change, and sensitive file transfer are a good starting list. For each one, write down who can approve it, what evidence is required, and which second channel must be used to verify it.
Then test the process with the people who actually answer calls. A policy that only lives in a binder will not help the receptionist, office manager, finance assistant, or help-desk technician who gets pressured in real time. The goal is a workflow simple enough to use when someone is busy and cautious enough to hold up when the voice on the line sounds familiar.
Sources and further reading