Global Scam IntelligenceDaily updates on global scam news and tactics
← Back to home
AI Voice ScamsPublished: September 26, 2026Italy

Italian Bank Loses €95 Million in AI-Powered Voice Cloning Fraud

Italy's largest bank, Intesa Sanpaolo's private banking subsidiary Fideuram, lost €95 million to fraudsters using AI-generated voice clones and spoofed WhatsApp messages. Criminals impersonated senior executives and convinced bank officials to wire funds to Asian accounts, with €53 million recovered but approximately €36 million converted to cryptocurrency and still missing.

How the Scam Worked

The fraud began in February when Paolo Molesini, chairman of Fideuram, received a WhatsApp message purporting to be from Intesa Sanpaolo's CEO Carlo Messina requesting urgent assistance with an overseas transaction. Shortly after, a person claiming to be a senior partner at a prominent law firm called to confirm the request. The fraudsters had used artificial intelligence to recreate the lawyer's voice convincingly.

Believing the requests were legitimate, Molesini instructed the finance department to wire approximately €95 million, primarily to accounts in China and Hong Kong. The scammers successfully exploited the chain of confirmation across multiple communication channels.

Recovery and Losses

Fideuram detected the irregular transactions quickly and alerted authorities in multiple countries. Coordinated investigations by law enforcement in China, Portugal, and Italy resulted in the recovery of approximately €53 million. However, roughly €36 million remains missing after being transferred through overseas accounts and converted into cryptocurrency.

Why This Scam Was Effective

Key factors enabling the fraud:

  • Accessible Voice Samples: High-quality audio of executives is readily available through media appearances, interviews, and published videos. Only a few seconds are needed to create a convincing voice clone
  • Difficult to Detect: Unlike traditional voice fraud, AI-generated voices exhibit no obvious signs of deepfaking to the untrained ear
  • Traditional Safeguards Fail: Standard verification procedures such as calling back an executive's known number provide little protection when the fraudsters control the callback as well
  • Social Engineering: The combination of a formal WhatsApp message followed by a confirming phone call creates false legitimacy through multiple touchpoints

Prevention and Detection Strategies

For individuals and employees:

  • Never execute high-value transfers based solely on digital communication, even if it appears to come from senior management
  • Verify unusual requests through previously established channels or in-person meetings
  • Be suspicious of artificial urgency or requests that circumvent normal approval procedures
  • Request unusual transactions be confirmed through multiple independent methods

For financial institutions and corporations:

  • Implement multi-channel approval processes requiring different individuals to confirm large transactions through separate communication channels
  • Establish and communicate predetermined code words or verification protocols for emergency requests
  • Deploy voice authentication tools such as Pindrop or Reality Defender to detect AI-generated audio in real time
  • Conduct regular security audits and staff training on deepfake and social engineering tactics
  • Set transfer limits that require in-person or multi-party verification

Where to Report Suspected Fraud

  • Your financial institution's fraud department
  • Local law enforcement
  • Financial regulatory authorities
  • International cybercrime reporting centers (FBI's IC3, Europol, Interpol)
  • Your country's financial intelligence unit

Source: Trending Topics

Share