Ropes & Gray·CYBERSECURITY

Asset Managers Face AI-Powered Phishing and Voice-Clone Attacks

Sophisticated attacks use generative AI to clone executive voices and bypass multi-factor authentication, raising regulatory scrutiny in the UK and EU.

Attackers are deploying increasingly sophisticated social engineering campaigns against hedge funds and other asset managers, leveraging generative AI to create convincing synthetic voice and video replicas of senior executives. The new wave of "vishing" (voice phishing) and spearphishing attacks uses meticulously researched pretexts from public investor communications and can bypass common multi-factor authentication (MFA) through methods like adversary-in-the-middle proxies.

This escalation of cyber threats presents a distinct risk for alternative investment managers, who are attractive targets due to the high value of the data they process and their typically leaner security infrastructure compared to major banks. Regulators in both the UK and the EU are responding with heightened expectations. The UK's Financial Conduct Authority (FCA) and the EU's Digital Operational Resilience Act (DORA) both require firms to ensure their systems and controls are robust enough to withstand such targeted, AI-enabled attacks. Senior managers may face personal liability for control failures. Firms should immediately consider adopting phishing-resistant MFA, implementing zero-trust architecture, training staff with realistic vishing simulations, and reviewing cyber insurance policies for relevant coverage gaps.

cybersecurityasset-managementphishingaifinancial-regulationfcadoravishing
Read the original firm alert → Friday, September 4, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.