---
title: "How a Cloned Voice Moved €95 Million Out of an Italian Bank"
published: 2026-09-29T00:03:51.094Z
updated: 2026-09-29T00:04:04.827Z
author: "Trust Onion Editorial Team"
canonical: https://trustonion.io/blog/ai-voice-clone-wire-fraud-italian-bank-95-million
---

# How a Cloned Voice Moved €95 Million Out of an Italian Bank

**Cite as:** How a Cloned Voice Moved €95 Million Out of an Italian Bank, Trust Onion, 2026-09-29. https://trustonion.io/blog/ai-voice-clone-wire-fraud-italian-bank-95-million

A fake WhatsApp message and a cloned voice were enough to move €95 million out of one of Italy's most prominent private banks. The chairman of Fideuram, Paolo Molesini, received what appeared to be a message from Intesa Sanpaolo CEO Carlo Messina, followed by a phone call from someone posing as a senior law firm partner. Molesini authorized the transfers. The bank later recovered approximately €53 million through international cooperation. Roughly €36 million was converted to cryptocurrency and is still missing.

## The Attack, Step by Step

The fraud against Fideuram followed a pattern that is becoming more common in corporate finance: a trusted name, a plausible story, and a sense of urgency.

Fraudsters sent a WhatsApp message impersonating Carlo Messina, CEO of Intesa Sanpaolo, Fideuram's parent group. The message established context and credibility. Then came the phone call, a voice cloned to sound like a senior law firm partner, providing what sounded like authoritative legal cover for a series of overseas wire transfers.

Molesini instructed Fideuram's finance department to move the funds to accounts in China and Hong Kong. The total: €95 million.

The bank's anomaly detection systems eventually flagged the transfers. With international law enforcement cooperation, about €53 million was recovered. The remaining €36 million had already been converted into cryptocurrency and is gone. Milan prosecutors placed at least one foreign national under investigation for computer fraud. Molesini resigned.

## Why This Attack Worked

The combination of a text message and a follow-up phone call is deliberate. The message primes the target. The voice call closes the deal.

Voice cloning now requires as little as 20 to 30 seconds of audio. Executives give speeches, appear in earnings calls, and conduct media interviews, so their voices are publicly available. A motivated fraudster can build a convincing audio model from material that is already online.

The law firm impersonation added a second layer of apparent authority. The caller was not asking for the transfer; the caller was confirming it was legally sanctioned. That framing shifts the psychology: the target is no longer approving an unusual request, they are complying with an already-established decision.

This is a social vulnerability, not a technical one. The attack exploited the normal way senior executives communicate, through trusted names, informal channels, and verbal authorization.

## The Scale of the Problem

The Fideuram case is not an outlier. In February 2024, engineering firm Arup lost $25 million after an employee joined a video call where every participant, including the CFO, was a deepfake. The employee transferred funds based on instructions given during that call.

According to the FBI's Internet Crime Complaint Center, business email compromise and related fraud schemes cost U.S. organizations more than $2.9 billion in 2023 alone. Voice fraud is pushing that figure higher. The World Economic Forum reported a 500% increase in deepfake fraud attempts in 2024.

The common thread across these incidents is not a failure of technology. It is a failure of verification. Organizations have no standard protocol for confirming, in real time, that the person authorizing a significant financial action is actually who they say they are.

## What Finance Teams Are Missing

Most organizations rely on one or more of the following when handling executive payment requests: caller ID or contact name recognition, familiarity with the executive's voice, the apparent logic of the request, or a follow-up email confirming the instruction.

None of these hold. Caller ID can be spoofed. Voice can be cloned. A plausible story is part of the attack design. A follow-up email from a compromised or spoofed account confirms nothing.

Calling back the number that contacted you is not a reliable check either. Fraudsters can maintain spoofed lines or use intermediaries who stay in character. If you verify through a callback, use a number sourced independently from your organization's own records, not the number that appeared in the original call or message.

The underlying problem is structural. Finance teams have no shared secret with the executives they take instructions from, nothing that the real executive knows and a fraudster cannot fake.

## The Operational Control That Stops This

Trust Onion gives finance teams exactly that: a shared secret that rotates every 60 seconds and cannot be guessed, cloned, or intercepted.

The concept is straightforward. Everyone in a verified authorization chain carries three rotating codewords, generated locally on each device with no server required. When an executive calls to authorize a wire transfer, a vendor payment change, or any high-stakes action, the finance team member asks one question: "What are the words?"

The real CFO answers correctly. An impersonator cannot. The words that were valid 90 seconds ago have already expired, so a recorded answer from a previous call is useless.

For situations where a voice call is not possible or not trusted, Trust Onion offers Proofies: a verified selfie with the current three codewords overlaid and cryptographically signed. An executive can send a Proofie before a large approval, giving the finance team a timestamped, tamper-evident identity confirmation.

If Fideuram's finance department had been operating under a codeword protocol, the fraudster's cloned voice would have hit a wall the moment someone asked: "What are the words?" The call would have ended there. The €95 million would not have moved.

## Building the Habit Before the Attack Arrives

Adding an executive verification layer is not complicated. The challenge is making it a standing operational requirement before a fraud attempt, not a reaction to one.

The policy is simple: no wire transfer, no vendor account change, no large payment approval proceeds without the caller providing the current codewords. The policy applies regardless of who is calling, the CEO included, especially the CEO.

This removes the social pressure that makes these attacks effective. A finance team member does not need to judge whether the caller sounds right, whether the story is plausible, or whether questioning a senior executive will cause offense. The question is neutral and non-negotiable: "What are the words?"

Trust Onion is free to deploy, works offline, and requires no integration with existing systems. Any finance team can activate it today.

The €36 million still missing from Fideuram's accounts shows what happens when authorization depends entirely on trust in a voice.

<!-- trust-onion:voice-clone-demo-disclosure -->

## A controlled voice-cloning safety demonstration

[Try our tool to see just how easy voice cloning is](/clone-my-voice). This controlled safety demonstration exists only to show how easy voice cloning is and to make the risk tangible. It is not a real incident or proof of anyone's identity. Your submitted sample is handled transiently to generate the fixed demonstration audio. Trust Onion does not identify you or the person from the sample. Trust Onion does not store the submitted recording, clone, or generated audio.

## Key takeaways

- Fraudsters used a cloned voice and a fake WhatsApp message to authorize €95 million in wire transfers from Fideuram in 2026.
- Roughly €36 million was converted to cryptocurrency before recovery efforts and remains missing.
- Voice cloning requires as little as 20 to 30 seconds of audio, making any public-facing executive a potential target.
- A callback to the number that called you does not confirm the original caller was legitimate; always use independently sourced contact information.
- A rotating codeword protocol gives finance teams a shared secret that an impersonator cannot fake, even with a perfect voice clone.

## Frequently asked questions

### How did scammers steal €95 million from Fideuram?

Fraudsters sent a fake WhatsApp message impersonating Intesa Sanpaolo CEO Carlo Messina, then followed up with an AI-cloned phone call posing as a law firm partner. Fideuram Chairman Paolo Molesini authorized the transfers. Roughly €36 million remains unrecovered after being converted to cryptocurrency.

### Can AI really clone an executive's voice convincingly enough to fool a finance team?

Yes. Voice cloning now requires as little as 20 to 30 seconds of audio. Executives who appear in earnings calls, media interviews, or public events provide more than enough source material. Human detection accuracy for cloned voices hovers around 55 to 60 percent, barely better than a coin flip.

### Is calling back the number that contacted you a safe way to verify an executive request?

No. A failed callback does not prove the original caller was legitimate. Fraudsters can maintain spoofed lines or use intermediaries. Always use a number from your organization's own independently sourced records, not the number that appeared in the original call.

### What is a rotating codeword protocol and how does it stop voice fraud?

A rotating codeword protocol gives every verified team member access to three shared codewords that change every 60 seconds. A finance team member asks any caller claiming to be an executive: 'What are the words?' A legitimate executive answers correctly. An impersonator cannot, regardless of how convincing their voice sounds.

### How much does it cost to add executive call verification to a finance team?

Trust Onion is free. It works offline, requires no server, and can be deployed across an entire organization without technical integration. The codewords rotate automatically and expire, so a compromised word becomes useless within 60 seconds.

## More from Trust Onion

Add Trust Onion's rotating codeword check to every executive approval and wire transfer request. Three words, verified in seconds, free for your entire team.

**Safety note:** If you cannot reach the person or organization when you call back, do not assume the original caller was really them. For a family call, if the caller cannot confirm your private Trust Onion Three Words, it could still be a scam; for a bank or other organization, verify through the official app or a number from a card or statement. Always use your best common-sense judgment, and alert the authorities if you believe someone is in danger.
