← All posts / Meta

€95 Million, One Fake WhatsApp: Inside the AI Fraud That Hit Italy's Largest Bank

Fraudsters combined a spoofed WhatsApp identity with an AI-cloned voice to extract €95 million from Fideuram, the private banking arm of Intesa Sanpaolo — the largest known AI-enabled theft from a single financial institution.

€95 Million, One Fake WhatsApp: Inside the AI Fraud That Hit Italy's Largest Bank

The scam started the way scams now do: with a message that looked like it came from the boss.

Sometime in February 2026, Paolo Molesini — then chairman of Fideuram, the private banking arm of Intesa Sanpaolo, Italy’s largest bank — received a WhatsApp message that appeared to come from a senior Intesa executive, according to sources familiar with the matter who spoke to Reuters. The number was fake. The display name was not. What followed was a carefully staged sequence of AI-generated voice calls impersonating a lawyer, culminating in a series of wire transfers totalling roughly €95 million ($108 million). About €59 million has been recovered or frozen. Approximately €36 million is still missing.

If the mechanics sound familiar, the scale is not. This is not a €25 million deepfake video call in Hong Kong or a €220,000 cloned-CEO voice from 2019. This is the largest publicly known AI-enabled fraud against a single financial institution, and it was pulled off not against a mid-level finance clerk but against the chairman of one of Europe’s most conservative private banks.

How the scam worked

The attack, reconstructed from reporting by Reuters, Il Sole 24 Ore, and Italian press, unfolded in three stages:

Stage 1 — The spoofed WhatsApp. Fraudsters registered or spoofed a WhatsApp account displaying the name of a senior Intesa Sanpaolo executive — reporting indicates the impersonated identity was tied to Intesa’s CEO Carlo Messina’s office — and sent an urgent, plausible message to Molesini. The pretext was a confidential, time-sensitive corporate matter that required discretion.

Stage 2 — The cloned voice. To close the trust gap, the criminals used AI voice cloning to impersonate a lawyer known to or plausible within the transaction. A phone call in a familiar voice is a powerful authentication token — and it is now trivially cheap to forge. Voice cloning from a few seconds of sampled audio is a commodity capability in 2026, available in consumer-grade tools.

Stage 3 — The wires. Molesini, believing he was acting on legitimate instructions, authorised transfers from Intesa Sanpaolo accounts to third-party accounts controlled by the fraud network. The funds were dispersed through mule accounts across jurisdictions. Italian authorities have since frozen about €59 million; roughly €36 million remains untraced, and Il Sole 24 Ore reports the former chairman has separately faced questions over the disappeared sum.

Why this matters beyond Italy

The authentication model is broken. Banks have spent two decades building multi-factor authentication around accounts — passwords, OTPs, hardware tokens. This attack bypassed all of it because the compromise was not of an account but of a relationship. The fraudsters didn’t need Molesini’s credentials. They needed him to believe a message. In an environment where a voice can be cloned from a podcast clip and a WhatsApp identity can display any name, the trust signals humans rely on — caller ID, a familiar voice, a known name — are no longer evidence of identity.

Private banking is the soft target. Fideuram’s business model is discretion. Clients and executives move large sums on personal instructions, often outside standardised corporate payment workflows precisely because the amounts are sensitive. That culture of informal, relationship-based authorisation — the same trait that lets a Swiss businessman be duped by a cloned business partner’s voice, as happened in January 2026 — is exactly what AI impersonation attacks are optimised to exploit.

The numbers are getting worse, fast. The Thomson Reuters Institute reported this week that victim losses from financial scams reached roughly $20 billion in 2025, up 26% year over year, with AI-driven deception cited as a primary accelerant. Italy’s own Financial Intelligence Unit has reported a significant surge in suspicious transaction reports tied to AI-enabled fraud. The Fideuram case is the new ceiling, not the trend line.

The control gap

The uncomfortable lesson from Milan is that the vulnerability was procedural, not technological. No firewall failed. No encryption was broken. A human with legitimate authority made a decision based on forged social proof.

The controls that would have stopped this are unglamorous: out-of-band verification callbacks on hardcoded numbers; mandatory dual authorisation for transfers above thresholds regardless of who requests them; deliberate latency — a cooling-off period that breaks the urgency the scam depends on; and explicit policies that no instruction received via WhatsApp, voice call, or any single channel is ever sufficient to move money. Australia’s corporate regulator has been pushing exactly this “verification break” doctrine after a wave of similar incidents.

There is also a harder question for the industry: when the chairman himself is the attack surface, whose job is it to say no? Fideuram reportedly relied on the assumption that senior people are harder to fool. The fraud inverted that assumption deliberately — targeting the person whose instructions are never questioned.

What happens next

Intesa Sanpaolo has not disclosed the full investigative picture, and the case is with Italian judicial authorities. Reuters’ reporting characterises the incident as a source-based disclosure rather than a bank announcement — which itself signals how sensitive the reputational exposure is for a bank that markets trust as its core product.

Expect three follow-on effects. First, European private banks will face regulator pressure to impose hard verification breaks on executive-initiated transfers, and the ECB’s supervisory arm has already flagged AI-enabled fraud as a 2026 thematic priority. Second, the insurance market for social engineering loss — already tightening — will reprice after a nine-figure loss at a systemically significant institution. Third, the case becomes the reference point in the debate over liability when AI impersonation defeats human judgment: is the bank liable for failing to prevent it, or does the fraud merely exploit the boundary of what any reasonable control could stop?

The €36 million still missing may be the least of it. What the Fideuram case demonstrates is that the marginal cost of convincing a specific, sophisticated, well-defended human to act against their own institution’s interests has fallen to the cost of a phone call. Every organisation that moves money on the strength of a voice now has a Milan problem.