cyberivy
AI Voice FraudVoice CloningDeepfakesSocial EngineeringBanking SecurityFideuramIntesa SanpaoloCybersecurity

AI voice tricks Fideuram into a €95 million transfer

October 3, 2026

Ein Smartphone mit geöffnetem WhatsApp-Bildschirm liegt auf einer hellen Oberfläche

Fraudsters combined a fake WhatsApp message with a cloned voice. Fideuram transferred about €95 million, though investigators recovered a large share.

What this is about

Fideuram, the private-banking arm of Italy's Intesa Sanpaolo, was defrauded of about €95 million, according to consistent media reports. The attack began in February 2026 with a WhatsApp message that appeared to come from Intesa Sanpaolo chief executive Carlo Messina. A subsequent call using the cloned voice of a prominent lawyer supposedly confirmed the urgent overseas transfer. Reuters published its investigation on October 2, 2026.

The case matters to ordinary businesses because the attackers did not exploit an exotic technical vulnerability. They attacked a familiar business process: an important person requests something urgent, a second apparently credible person confirms it, and employees execute the order. Generative voice systems make that acoustic confirmation cheaper and more convincing.

What the attack actually did

According to the reports, then-Fideuram chair Paolo Molesini received a message framed as a request from the group chief executive for help with a confidential transaction. Soon afterward, a caller claimed to be a senior partner at a prominent law firm. The attackers allegedly recreated that lawyer's voice with AI. Funds were then transferred mainly to accounts in China and Hong Kong.

Fideuram detected irregularities and contacted authorities in several countries. Published figures differ in detail: reporting based on Reuters puts the total at about €95 million; Trending Topics says roughly €53 million was secured, while AML Intelligence says about €36 million remained missing after further transfers and conversion into cryptocurrency. Those figures do not amount to a complete, publicly audited reconciliation.

The combination of signals is crucial. The message supplied authority and urgency. The call created seemingly independent confirmation. International accounts and cryptocurrency then made recovery harder. The cloned voice was therefore not the entire attack but one component in a carefully constructed social-engineering sequence.

Why it matters

Many organizations still treat a callback or recognizing a voice as a security control. That assumption is no longer dependable. Voices of executives, lawyers, and other public figures are readily available in interviews, podcasts, and videos. Convincing replicas can be made from such material.

The loss also shows how hierarchy can create risk. The more senior the supposed requester and the more confidential the claimed transaction, the more likely normal questions are to be skipped. A sound payment process must not depend on whether a voice sounds familiar. It needs technical and organizational controls: pre-registered contact routes, dual approval, transaction limits, waiting periods for new recipients, and confirmation through a separate system.

The same principle applies to individuals on a smaller scale. A call that sounds like a family member is not proof of identity. When money is requested, hang up and call back using a known number you selected yourself.

In plain language

Imagine someone arrives wearing your colleague's jacket and speaking in your colleague's voice. You still would not automatically hand over the safe key. A voice is now like that jacket: a familiar feature, not proof. The key should be released only after a second, independent check.

A practical example

A finance director receives a message at 4:40 p.m. from the supposed chief executive: €480,000 must reach a new supplier before the bank closes. Two minutes later, a familiar-sounding voice confirms the instruction. In a weak process, that is enough.

A resilient process automatically pauses the payment because the recipient is new and the amount exceeds €100,000. A second authorized person must approve it in the payment portal. The finance director also calls the chief executive using the number stored in the company directory and asks for an internal case code. If any check cannot be completed, the money stays put. The control therefore does not ask whether the voice sounds real; it asks whether the full transaction follows rules agreed in advance.

Scope and limits

  • The exact voice-cloning technique has not been documented publicly through a forensic report. The reporting does not establish which model was used or how much training material the attackers collected.
  • Published amounts recovered and still missing are snapshots from an active investigation. They may change and are not a final loss statement from the bank.
  • Voice detection can provide an additional warning but cannot reliably prevent fraud. Strong fakes, poor connections, and genuine speakers sounding unusual can all produce wrong decisions. Payment approval must therefore work independently of audio analysis.

The case also does not show that every large fraudulent transfer involves AI. Forged email, compromised accounts, and human pressure remain important. The lesson is narrower: speech can no longer serve as the sole proof of identity for a risky transaction.

SEO & GEO keywords

Fideuram, Intesa Sanpaolo, AI voice fraud, voice cloning, deepfake fraud, social engineering, payment approval, WhatsApp fraud, banking security, business email compromise

💡 In plain English

A familiar voice on the phone no longer proves who is speaking. Large payments need at least one independent approval through a channel agreed in advance.

Key Takeaways

  • →Fideuram transferred about €95 million after a forged message and a call using a cloned voice.
  • →Investigators reportedly secured a large share, but the final loss has not been publicly confirmed.
  • →The cloned voice was one part of a multi-stage social-engineering attack.
  • →Voices must not serve as the sole proof of identity for payments.
  • →Dual approval and separate confirmation channels reduce the risk.

FAQ

How large was the transfer?

Reports put it at about €95 million. The amount ultimately lost has not yet been confirmed in a final public account.

Was the cloned voice the only cause?

No. The attackers combined a forged message, authority, time pressure, a confirming call, and international payment routes.

Does calling back prevent voice fraud?

Only when the number is selected independently from a trusted directory. Calling a number supplied in the suspicious message is not a reliable safeguard.

What is the most important control?

Large or unusual payments should require several independent approvals, especially when the recipient is new.

Sources & Context