Italian bank loses €95M in AI voice-clone executive fraud
Fraudsters used artificial intelligence to clone the voice of a lawyer and spoof WhatsApp messages from a senior executive, tricking Fideuram—the private-banking arm of Intesa Sanpaolo, Italy's largest lender—into authorizing €95 million (about $108 million USD) in wire transfers to accounts in China and Hong Kong, Reuters reported on September 25, 2026.
How the scam unfolded
The operation began in February 2026, when Paolo Molesini, then chairman of Fideuram, received a WhatsApp message that appeared to come from Carlo Messina, CEO of Intesa Sanpaolo, requesting assistance with an overseas transaction. The fraudsters later deployed an AI-generated voice replicating that of a lawyer—identified as Nastasi in reporting—to add credibility to follow-up communications. Molesini subsequently instructed Fideuram's finance department to arrange the transfers, which flowed to accounts mainly in China and Hong Kong.
Recovery and ongoing losses
More than half the stolen funds were later recovered through a coordinated international effort. Authorities in China, Portugal, and Italy cooperated to trace and freeze assets, resulting in the recovery of approximately €53 million. However, approximately €36 million remains missing, underscoring the difficulty of pursuing cross-border financial crime even when the initial fraud is detected.
The incident represents one of the largest documented cases of AI-enabled voice cloning used in a targeted social-engineering attack on a financial institution. Unlike mass phishing campaigns, this operation relied on personally tailored impersonations of known executives—a technique that exploits both institutional trust hierarchies and the difficulty of voice authentication at scale.
Implications for banking security
The Fideuram case demonstrates that voice-cloning technology, combined with messaging-platform spoofing, can overcome multi-layered organizational controls. Senior executives remain high-value targets because their directives carry institutional weight and bypass normal verification procedures. The attack's success—despite occurring at one of Europe's most established financial institutions—suggests that traditional identity-confirmation workflows may be inadequate against AI-powered impersonation.
No court charges, convictions, or formal regulatory enforcement actions have been publicly disclosed at this time. The banks and authorities involved have not issued detailed statements on preventive measures adopted following the breach.