Security
€95 Million Left Italy's Biggest Private Bank on a WhatsApp Message and One Phone Call. The Deepfake Is the Least Interesting Part
Fraudsters impersonating Intesa Sanpaolo's CEO and a real lawyer moved €95 million out of Fideuram in February; €53 million was clawed back and at least €36 million is gone. The cloned voice was not the failure — it was the verification step, supplied by the attackers.
MAI
Reuters reported on Friday that fraudsters impersonating senior executives moved €95 million ($108 million) out of Fideuram, the private banking arm of Intesa Sanpaolo, Italy's largest lender. The theft happened in February. It is being reported now, seven months later, because two people familiar with the matter described it to Reuters — not because either bank disclosed it.
The technique involved an AI-generated voice. That is the detail every headline has led with, and it is the least interesting part of the case. What moved the money was not a convincing impersonation. It was a payment process in which a single senior person's belief could reach the treasury desk.
What happened
In February, Paolo Molesini, then chairman of Fideuram, received WhatsApp messages presented as coming from Carlo Messina, chief executive of parent company Intesa Sanpaolo. The messages described urgent international transfers that needed to go through Fideuram's treasury department. A follow-up telephone call used a synthetic replica of the voice of a managing partner at the Italian practice of law firm A&O Shearman — a real lawyer, named in the Italian press, who had nothing to do with any of it and whose apparent involvement served to make the request look validated.
Molesini authorised the transfers. The money went to accounts mainly in mainland China and Hong Kong. He resigned as chairman in March, citing personal reasons. Reuters reports that neither he nor other Fideuram executives are under investigation by their own institution. Milan prosecutors have placed a foreign national resident outside Europe under investigation for computer fraud. Intesa Sanpaolo and Fideuram declined to comment.
| Amount | |
|---|---|
| Transferred out of Fideuram | €95m (about $108m) |
| Identified and frozen by a Chinese bank, then returned | €40m |
| Traced to Portugal and seized before onward transfer | €13m |
| Still missing, partly converted into cryptocurrency | at least €36m |
The published figures do not fully reconcile — Reuters says more than half was recovered, Il Sole 24 Ore accounts for €53 million returned or seized, and at least €36 million remains gone. Nobody has offered a public breakdown of the difference.
The synthetic voice was the second factor
Fideuram did not skip verification. Verification is what the cloned voice was for.
A message arrives claiming to be from the group CEO. The recipient wants corroboration, and corroboration arrives: a call from a lawyer at a firm the bank knows, confirming the transaction. The check was performed. The problem is that the adversary supplied both the request and the thing that confirmed it, because both travelled over channels the adversary had chosen. An out-of-band check is only out-of-band if the defender picks the band.
This is why "train staff to spot deepfakes" is the wrong response to this case, and it is the response most institutions will reach for. Voice synthesis good enough to pass a phone call is commodity technology and has been for two years. A control that depends on a human ear beating it is not a control. The control that works is procedural and dull: a callback to a number retrieved from the internal directory rather than the one that made contact, a second authoriser who is told nothing about urgency, and a standing rule that no transfer is released on the strength of a voice — any voice.
There is a governance point underneath. The person deceived here was the chairman. Payment controls are written to be overridden by sufficient seniority, and Fideuram had a treasury function that could be instructed by a chairman and a chairman who could be reached by anyone with his phone number. The deepfake exploited a hierarchy, not a system.
Recovery was a property of the rails, not of the bank
What got €53 million back was the banking system's ability to reverse itself. A Chinese bank identified and froze €40 million and returned it. Italian prosecutors, working with Lisbon counterparts through Eurojust, found €13 million in Portugal and seized it before it moved on. None of that was detection — the bank had already sent the money. It was correspondent banking plus mutual legal assistance, and it worked because Fideuram reported quickly.
The €36 million that is gone is the portion converted into cryptocurrency. There is no counterparty to telephone. That asymmetry is the practical lesson: a wire has an owner who can be compelled, and once value leaves that system, the recovery mechanism is not slower, it is absent.
Italy has seen this before
In early 2025, fraudsters using an AI replica of the voice of Italian defence minister Guido Crosetto solicited money from Italian businessmen. Massimo Moratti transferred nearly €1 million, later recovered. Same country, same method, a year before Fideuram, and extensively covered at the time.
The gap between that warning and a €95 million loss at a systemically important bank is the part supervisors should be asking about. Europe's Digital Operational Resilience Act has been in force since January 2025 and frames this sort of thing as ICT risk. Almost nothing about this incident was an ICT failure. No system was breached, no credential was stolen, no software was defective. A bank's chairman was persuaded, and the institution's payment authority had no floor beneath him. That is a governance question, and the synthetic voice is only what made the answer expensive.
Sources: Reuters, Emilio Parodi (via TradingView) · Reuters via The Express Tribune · Il Sole 24 Ore · Reuters Legal on X · AML Intelligence · Gulf News · L'Unione Sarda · Intesa Sanpaolo press kit