Blog
Corporate Wire Fraud (Voice Clone)

AI Voice Clone and Fake WhatsApp Cost Italian Bank €95M

A spoofed WhatsApp message and an AI-cloned voice were all it took to convince the chairman of Fideuram, one of Italy's largest private banks, to authorize roughly €95 million in wire transfers to accounts in China and Hong Kong. International investigators recovered about €53 million. Around €36 million has not been found.

voice cloning identity verification ai threat

Part of our Voice Cloning Scams topic guide.

By Jesse Seaver, Co-Founder, Trust Onion

Published October 1, 2026

Filed to the News Desk · Corporate Wire Fraud (Voice Clone)

Originally reported by Gadget Review · Read the original article


Key Takeaways
  • Fraudsters combined a spoofed WhatsApp message and an AI-cloned voice to steal approximately €95 million from Fideuram chairman Paolo Molesini in 2026.
  • The two-channel approach manufactured the appearance of independent corroboration, making the fraudulent instruction far more convincing.
  • Roughly €36 million remains untraced after passing through overseas accounts and being converted to cryptocurrency.
  • Standard transaction controls address the payment but not the authorization behind it, which is where the fraud actually occurs.
  • A rotating codeword challenge inserted before any wire authorization would have exposed the impersonator before a single euro moved.

How Two Trusted Sources Became One Coordinated Attack

In late September 2026, fraudsters ran a two-channel scheme against Paolo Molesini, chairman of Fideuram, a subsidiary of Intesa Sanpaolo. The attack combined a spoofed WhatsApp message impersonating Intesa Sanpaolo CEO Carlo Messina with an AI-cloned voice impersonating a senior partner at a trusted law firm.

Neither channel alone would have convinced a senior executive. That was the point. By running both at once, the attackers manufactured the appearance of independent confirmation: a written instruction from the CEO, a verbal endorsement from legal counsel, two sources, two channels, one fraudulent outcome.

The Architecture of the Attack

This fraud exploits a specific cognitive shortcut: corroboration implies legitimacy. When two trusted contacts appear to confirm the same instruction at the same time, recipients are far less likely to pause and verify.

Voice cloning now requires as little as 20 to 30 seconds of audio to produce a convincing replica. Earnings calls, investor presentations, and media interviews give fraudsters more than enough raw material to clone a senior executive or a named professional. WhatsApp spoofing adds a written layer that looks familiar and trusted, and each channel reinforces the other.

Why Senior Executives Are Targeted

Attacks on high-level targets follow a different logic than standard phishing. Fraudsters don't need to compromise systems. They need to compromise judgment. A chairman authorizing a large international transfer is doing something within his normal authority. The action itself isn't unusual. Only the instruction behind it is fraudulent.

According to the FBI's Internet Crime Complaint Center, business email and voice compromise schemes resulted in losses exceeding $2.9 billion in 2023 alone. The Fideuram case suggests that figure will rise as voice cloning becomes cheaper and more accessible.

What Standard Controls Miss

Most organizations build fraud controls around transaction size and destination. Large international transfers trigger review. Unusual counterparties raise flags. Those controls matter, but they address the transaction, not the authorization behind it.

When the chairman of a major financial institution authorizes a transfer, the assumption is that the authorization has been properly vetted. This fraud didn't defeat a technical control. It defeated the human verification step that sits before any control is triggered. The attacker didn't hack a system. The attacker replaced a person.

Callback Limitations

A common recommendation after cases like this is to call back on a known number before approving any large transfer. That's a reasonable step worth taking. But a completed callback doesn't confirm the original caller was legitimate. It only confirms you reached the real person the second time. A sophisticated attacker who has already moved funds isn't waiting for your callback.

For any large wire authorization, verification must happen before approval, not after the funds have moved. If someone appears to be in danger or under duress during a high-stakes approval, alert authorities directly.

The Gap in the Verification Chain

The Fideuram case shows what happens when organizations treat voice and written communication as inherently trusted channels. They aren't. Both can be fabricated, and both were fabricated here.

Organizations that authorize significant transfers, change payment instructions, or act on urgent executive requests need a verification layer that sits outside those channels entirely. Something the caller either knows or doesn't know. Something that can't be cloned from a public audio file or spoofed in a messaging app.

Trust Onion uses rotating three-word codewords, shared only within a verified chain of personnel. The words rotate every 60 seconds and are calculated locally on each device, with no server dependency. Before any wire authorization, the finance team member asks a simple question: "What are the words?"

The real executive knows them. An impersonator doesn't. A cloned voice can't answer.

In the Fideuram scenario, a codeword challenge inserted before the transfer authorization would have stopped the payment chain before the first euro left the account. An AI-generated voice, however convincing, can't produce three words it doesn't have.

For situations where the executive needs to confirm their identity proactively, Trust Onion also offers Proofies: a verified image with the current three codewords overlaid, timestamped and signed. An executive can send a Proofie before a high-stakes approval to confirm they are who they say they are. No phone call required. No channel that can be spoofed.

What Finance Teams Should Do Now

The operational change is straightforward. Identify every approval workflow where a verbal or written instruction from a senior executive can trigger a large payment, a vendor change, or a modification to banking details. Add a codeword challenge to each one.

This isn't a technology project and doesn't require new infrastructure. The words rotate on a schedule. The challenge takes three seconds. The protection is immediate.

Three words before any wire. That's the control that was missing in Italy.

€36 million is still missing. The window to recover it is closing. The window to prevent the next one is open right now.

A controlled voice-cloning safety demonstration

Try our tool to see just how easy voice cloning is. This controlled safety demonstration exists only to show how easy voice cloning is and to make the risk tangible. It is not a real incident or proof of anyone's identity. Your submitted sample is handled transiently to generate the fixed demonstration audio. Trust Onion does not identify you or the person from the sample. Trust Onion does not store the submitted recording, clone, or generated audio.

A lasting record of a place and time. Proofie™ images are stored on IPFS, a third-party distributed file network. Once created and shared, copies can’t be deleted everywhere by you, the recipient, us, or bad actors. So when you create a Proofie, you make a verifiable record of the place and time it captures.

Frequently Asked Questions

How did fraudsters steal €95 million from an Italian bank using AI?

Attackers used a spoofed WhatsApp message impersonating Intesa Sanpaolo CEO Carlo Messina and an AI-cloned voice impersonating a law firm partner to convince Fideuram chairman Paolo Molesini to authorize large international wire transfers. The two channels made the instruction appear to come from two independent trusted sources at once.

What is a two-channel voice and text fraud attack?

A two-channel attack combines a written message, such as a WhatsApp or email, with a phone or audio call to create the appearance of independent corroboration. When two seemingly separate trusted contacts confirm the same instruction, targets are much less likely to challenge it before acting.

How can finance teams verify executive wire transfer requests?

Finance teams should require a live verbal or written codeword challenge before approving any wire transfer or payment instruction change. Rotating codewords shared only with verified personnel can't be obtained from public audio, spoofed messages, or AI-cloned voices.

Does calling back on a known number confirm a caller's identity?

A successful callback confirms you reached the real person on a second attempt, but it doesn't prove the original caller was legitimate. For high-stakes approvals, verification must happen before the transfer is authorized, not after funds have already moved.

How much of the Fideuram fraud money was recovered?

International cooperation recovered approximately €53 million of the roughly €95 million transferred. Around €36 million remains untraced after passing through overseas accounts and being converted to cryptocurrency.

Add Trust Onion's rotating codeword check to your executive and wire-transfer approvals. Three words before every authorization, free for your entire team.

Protect Your Business Free

Cite this page

AI Voice Clone and Fake WhatsApp Cost Italian Bank €95M — Trust Onion, October 1, 2026. https://trustonion.io/blog/ai-voice-clone-fake-whatsapp-italian-bank-wire-fraud

RELATED READING

More on this topic

Fake Cop Calls Are Draining Bank Accounts in South Carolina

July 3, 2026

Fake Cop Calls Are Draining Bank Accounts in South Carolina

Beaufort County residents lost thousands to scammers posing as police. Here's how impersonation scam...

Read More
Bay Area Mom Wired $5,400 Before One Call Ended the Scam

May 26, 2026

Bay Area Mom Wired $5,400 Before One Call Ended the Scam

A Bay Area mom wired $5,400 to scammers who cloned her daughter's voice. One call to her daughter en...

Read More
AI Cloned His Daughter's Voice. He Almost Paid.

May 5, 2026

AI Cloned His Daughter's Voice. He Almost Paid.

AI scammers cloned a Vancouver man's daughter's voice to extort him. Here's how the scam works and w...

Read More