Amid all the recent reports of AI systems autonomously going off the rails and hacking into third-party organizations, it’s almost easy to forget that human hackers are still out there, experimenting with AI in all kinds of nefarious ways. A new report from Bloomberg, however, is a reminder of just how quickly AI-enabled cybercrime is evolving—and how unprepared the world is to deal with it. According to the report, a litany of high-profile hedge funds, including Citadel and Two Sigma, were targeted by recent voice phishing, or “vishing,” attacks, in which AI is used to simulate the voices of actual humans in an attempt to skirt security systems. Several private equity firms were also reportedly targeted. Two Sigma told Bloomberg that it caught the attack in time before any of its internal systems could be compromised; Citadel and Point72, another hedge fund included in the attack, did not immediately respond to Gizmodo’s request for comment. IT experts have been warning for years that the proliferation of cheap, easy-to-use AI tools that mimic human speech or generate other kinds of deepfake content will escalate both the severity of scam attempts and the rate at which they occur. The world got a taste of this in 2024, when an employee at the Hong Kong branch of a multinational company was duped into wiring more than $25.5 million to scammers who had instructed her to do so using AI-generated deepfakes of company employees, including its chief financial officer.