AI Voice Cloning Fraud: How €95M Left an Italian Bank
A fake WhatsApp message. A phone call from a lawyer who sounded exactly like the real one. A spoofed email with the account details. Together they moved €95 million out of Italy's biggest bank, and nobody had to hack a single system.
What happened at Fideuram
In February 2026, Paolo Molesini, then chairman of Fideuram, received a WhatsApp message that appeared to come from Carlo Messina, CEO of parent group Intesa Sanpaolo. It asked for urgent help with an overseas transaction.
A phone call followed from someone posing as a senior partner at a prominent law firm, confirming the request. Sources told Reuters the caller's voice was replicated with AI. According to Corriere della Sera, which first reported the case, a spoofed law-firm email then supplied the bank account details.
Molesini told the finance department to make the transfers, mostly to accounts in China and Hong Kong. Fideuram's internal controls later flagged them as irregular, and the bank alerted banks and authorities in several countries.
That speed mattered. Roughly €53 million has been recovered through cooperation between officials in China, Portugal and Italy, though some outlets report figures up to €59 million. About €36 million was converted to crypto and remains missing. Milan prosecutors are investigating a foreign national living outside Europe on suspicion of computer fraud.
Why the attack worked
Nothing here was technically sophisticated on the victim's side. The attackers built a small, convincing world around one person.
Three channels felt like three confirmations
Chat, phone and email all agreed with each other. The chairman had no reason to think they were all controlled by the same party.
A familiar voice skips the gut check
We trust voices we know. Cloning one now takes a short audio sample, and executives and lawyers leave plenty of it in interviews, panels and podcasts. If you want to see how synthetic speech gets caught, our audio detection page explains the approach.
Urgency and seniority shut down questions
A request from the CEO, marked urgent, rarely gets challenged. The attackers knew that.
Verification used the same compromised channels
Confirming a WhatsApp request with a phone call only works if the call is genuine. Here it wasn't.
Not a one-off
Coverage of the case reports that Intesa Sanpaolo has blocked thousands of AI-generated scam attempts aimed at its CEO since the start of 2026. Fideuram was the one that got through.
The pattern is familiar. In 2025, businessman Massimo Moratti sent nearly €1 million after fraudsters imitated Italy's defence minister by voice. That money was recovered. In 2024, an Arup employee in Hong Kong transferred about $25 million after a video call with faked colleagues. Live video is a separate problem, and it's why we built real-time deepfake detection for meetings.
More than half the money came back because the bank spotted the transfers and alerted authorities quickly. Detection speed decided the outcome.
What actually stops this
No single control would have. The organisations that avoid this loss combine process with technology.
Process controls
Verify out of band. Confirm any payment request through a pre-registered number or internal system, never the channel it arrived on.
Require dual approval above a set threshold, with no exemption for seniority.
Use a challenge phrase for high-value voice instructions, agreed in advance and never shared by message.
Slow down first-time overseas beneficiaries. A short delay costs little and gives fraud teams time to react.
Technical detection
Process fails when someone is convinced they don't need it. Detection tools don't get convinced. They check whether a voice, image, video or message shows the signs of synthetic generation, whoever it appears to be from. Our AI scam and deepfake detector is built for exactly that check, before money moves.
Frequently asked questions
How much money was stolen in the Fideuram scam?
€95 million, about $108 million. Roughly €53 million has been recovered, with some reports putting it as high as €59 million. About €36 million, converted to cryptocurrency, remains missing.
Was the bank hacked?
Public reporting describes impersonation and social engineering rather than a breach of the bank's systems. The attackers persuaded a senior person to authorise the payments.
Can a cloned voice be detected?
Often, yes. Synthetic speech tends to leave traces that detection models can pick up, although results vary by tool, audio quality and how recent the cloning technique is.
How can a company protect itself from voice cloning fraud?
Combine out-of-band verification, dual approval and challenge phrases with technical detection of synthetic media at the point where instructions arrive.
Are smaller businesses at risk too?
Yes. Voice cloning tools are cheap and widely available, and smaller firms often have fewer approval layers than a bank.
Trust the check, not the voice
The people at Fideuram did what most of us would do: they trusted a familiar name and a familiar voice. The fix is a system that verifies before anyone has to trust. Talk to us about putting one in place.
Talk to the UncovAI team →