Case Study
ai phone call

AI Voice Clone and Fake WhatsApp Drained €95 Million From Italian Bank

September 2026 · Executive · €95 million (approximately €36 million unrecovered) · Resolved

Fraudsters combined a spoofed WhatsApp message impersonating Intesa Sanpaolo CEO Carlo Messina with an AI-cloned voice impersonating a senior law firm partner to convince Fideuram chairman Paolo Molesini to authorize approximately €95 million in international wire transfers. The two-channel scheme made fraudulent instructions appear to originate from two independent, trusted sources at the same time. International cooperation recovered roughly €53 million, but approximately €36 million remains untraced after passing through overseas accounts and conversion to cryptocurrency.

By Jesse Seaver, Co-Founder, Trust Onion

Published October 1, 2026

Filed to the News Desk · ai phone call

Originally reported by Gadget Review · Read the original article

Part of our Voice Cloning Scams topic guide.

Definitions: Voice clone scam, AI voice cloning, Deepfake scam, Impersonation scam, CEO fraud / executive voice fraud

Timeline of Events

The Setup

Fraudsters gathered publicly available information on Intesa Sanpaolo CEO Carlo Messina, a senior partner at a law firm with ties to Fideuram, and Fideuram chairman Paolo Molesini. They prepared a spoofed WhatsApp account replicating Messina's identity and obtained or synthesized enough voice material to clone the law firm partner's voice convincingly.

The Attack

Molesini received a WhatsApp message from an account appearing to belong to Messina, instructing him to cooperate with an urgent, confidential international transaction. Shortly afterward, a caller using an AI-cloned voice of the senior law firm partner reinforced the instruction, providing apparent independent corroboration. Molesini authorized approximately €95 million in wire transfers, directed primarily to accounts in China and Hong Kong.

The Impact

Approximately €95 million left Fideuram accounts and moved through a chain of overseas accounts. A portion was converted to cryptocurrency, making tracing considerably harder. The dual-channel design gave the fraudulent instruction a false appearance of legitimacy from two independent, senior sources.

The Discovery

The fraud was identified after the transfers completed and the instructions could not be verified through legitimate channels. It became apparent that the WhatsApp account was spoofed and the phone caller was not the actual law firm partner.

The Fallout

International law enforcement cooperation recovered approximately €53 million. Approximately €36 million remains untraced, having moved through overseas accounts and been partially converted to cryptocurrency. The incident drew attention to gaps in wire-transfer authorization controls at financial institutions and the effectiveness of multi-channel AI fraud schemes.

Attack Details

The Fideuram fraud was a precisely engineered two-channel attack designed to manufacture the appearance of independent confirmation from two trusted sources. Fraudsters first spoofed a WhatsApp account to impersonate Intesa Sanpaolo CEO Carlo Messina, sending Fideuram chairman Paolo Molesini a message framing the forthcoming transfers as urgent and confidential. The written channel alone might have triggered skepticism, so they paired it with a follow-up phone call using an AI-cloned voice of a senior law firm partner known to Molesini, creating a second, apparently independent line of authority.

The two separate channels, one written, one spoken, exploited a well-documented psychological principle: corroboration from multiple independent sources increases perceived legitimacy. Molesini had no reason to suspect that both contacts were controlled by the same fraud operation. The voice clone was convincing enough that the caller's identity was not questioned during the call.

The transfer destinations, accounts in China and Hong Kong, were chosen for their distance from European regulatory reach and the speed with which funds could be moved onward. A portion of the proceeds was converted to cryptocurrency after leaving the initial receiving accounts, which complicated the asset tracing effort that followed.

The attack required no technical intrusion into Fideuram's systems. It succeeded entirely through social engineering at the executive authorization layer, the point in a financial institution's process where human judgment is the primary control. The fraudsters identified that layer as the weakest point and targeted it directly.

How Trust Onion Helps

Our analysis — prevention guidance, not part of the reported facts

Before authorizing any wire transfer, a finance or operations team member who asks the caller, 'What are the words?', would have immediately exposed the AI-cloned voice as fraudulent. The real law firm partner, had he actually been calling, would know the current three codewords shared within the authorized verification group. An impersonator controlling a voice clone cannot know those words because they rotate every 60 seconds and are calculated locally on each authorized device. There is no server to compromise, no database to breach, and no way to intercept the current codewords through call monitoring or social engineering alone.

The spoofed WhatsApp message would equally have failed a codeword challenge. Any protocol requiring written instructions from an executive to be accompanied by, or followed up with, the current three codewords would have stopped this attack before a single euro moved. The real Carlo Messina, had he sent the instruction, would have been able to provide the words. A fraudster controlling a spoofed account cannot.

The two-channel design of this attack was specifically intended to simulate independent corroboration and bypass individual skepticism. Trust Onion's rotating codeword check adds a shared-secret verification layer that neither channel can fake. A simple organizational policy requiring any wire transfer above a defined threshold to be accompanied by a codeword confirmation costs nothing to build, requires no technical infrastructure, and would have stopped this attack before authorization was given. Executives, finance teams, and legal advisors within the authorized group each hold the same rotating words. An impersonator, regardless of how convincing the voice or message, does not.

Impact Assessment

The immediate financial loss totaled approximately €95 million in authorized wire transfers. International cooperation between law enforcement agencies recovered roughly €53 million, leaving approximately €36 million untraced. The unrecovered funds had passed through multiple overseas accounts and been partially converted to cryptocurrency before investigators could freeze them, showing how quickly digital assets can move beyond practical reach.

Beyond the direct financial loss, the incident carries real reputational consequences for Fideuram and its parent group, Intesa Sanpaolo. A fraud of this scale against a senior executive of a major financial institution raises questions about the adequacy of internal authorization controls, particularly for large international transfers. Regulatory scrutiny of wire-transfer approval procedures is a foreseeable consequence.

The incident also signals a broader risk to the financial services industry. If a chairman-level executive at a sophisticated institution can be deceived by a spoofed message combined with an AI voice clone, no organization that relies solely on caller familiarity and message appearance as verification controls can consider itself adequately protected.

Cite this page

AI Voice Clone and Fake WhatsApp Drained €95 Million From Italian Bank — Trust Onion, October 1, 2026. https://trustonion.io/case-studies/ai-voice-clone-and-fake-whatsapp-drained-95-million-from-italian-bank

Lessons Learned

Multi-channel fraud schemes that combine written and voice impersonation are specifically designed to simulate independent corroboration. A single shared-secret verification step cuts through both channels at once.

AI voice cloning has reached a quality level where familiarity with a person's voice is no longer a reliable verification method. Finance teams need a verification control that voice cloning cannot replicate.

Wire-transfer authorization protocols that rely solely on caller identity and message appearance provide no defense against coordinated impersonation. A rotating codeword requirement adds a zero-cost control at the exact point where this attack succeeded.

Key Takeaways

Fraudsters stole approximately €95 million from Fideuram using a spoofed WhatsApp message and an AI-cloned voice, with approximately €36 million remaining unrecovered after cryptocurrency conversion.

The attack used two separate channels at once to create a false appearance of independent corroboration, bypassing the chairman's individual judgment.

No technical system breach was required. The fraud succeeded entirely by manipulating the human authorization layer for wire transfers.

International law enforcement cooperation recovered roughly €53 million, but funds converted to cryptocurrency moved beyond practical tracing reach quickly.

A rotating codeword challenge, required before any large wire transfer is authorized, would have exposed both the spoofed message and the AI voice clone as fraudulent before money moved.

Frequently Asked Questions

What happened in the Fideuram €95 million fraud incident?

Fraudsters sent Fideuram chairman Paolo Molesini a spoofed WhatsApp message impersonating Intesa Sanpaolo CEO Carlo Messina, then followed up with a phone call using an AI-cloned voice of a senior law firm partner. The two-channel approach simulated independent confirmation from trusted sources, leading Molesini to authorize approximately €95 million in wire transfers to accounts in China and Hong Kong.

How much money was lost and how much was recovered?

Approximately €95 million was transferred fraudulently. International law enforcement cooperation recovered roughly €53 million. Approximately €36 million remains untraced after passing through overseas accounts and being partially converted to cryptocurrency.

How could this wire transfer fraud have been prevented?

A codeword verification protocol would have stopped this attack before any funds moved. Trust Onion's rotating three-word codewords give finance teams a challenge they can issue to any caller claiming to be an executive or authorized advisor: 'What are the words?' The real executive or partner knows the current codewords. An AI voice clone does not. The words rotate every 60 seconds and are calculated locally on each authorized device, with no server to compromise. The same challenge applied to the written WhatsApp instruction would have exposed the spoofed account immediately. Add Trust Onion's rotating codeword check to executive and wire-transfer approvals at no cost.

Why was an AI voice clone used alongside a written message?

The two-channel design was deliberate. A single suspicious message or call might trigger skepticism. By combining a written instruction appearing to come from the group CEO with a follow-up call appearing to come from a trusted external legal adviser, the fraudsters manufactured the psychological effect of independent corroboration, making the instruction appear far more credible than either channel alone.

What made the funds so difficult to recover?

The transfers were directed to accounts in China and Hong Kong, outside European regulatory jurisdiction. A portion of the funds was then converted to cryptocurrency, which moves rapidly across borders and becomes much harder to trace and freeze. The combination of international account chains and cryptocurrency conversion placed a substantial portion of the funds beyond practical recovery.

Help Your Group Verify Calls

Friends, family, teams, and clubs can share three rotating words.
Ask the caller to give them first; compare privately in your app.

Download Free on the App Stores:

RELATED CASES

More case studies

AI Voice Clone and Fake WhatsApp Message Cost Italian Bank €95 Million
ai phone call

AI Voice Clone and Fake WhatsApp Message Cost Italian Bank €95 Million

Fraudsters impersonated Intesa Sanpaolo CEO Carlo Messina through a fake WhatsApp message to Fideuram Chairman Paolo Mol...

View Case Study
Michigan Couple Loses $66,000 in Real Estate Voice-Cloning Scam
voice cloning

Michigan Couple Loses $66,000 in Real Estate Voice-Cloning Scam

Michigan homebuyers identified as the VanDoeselaars lost $66,000 after scammers used suspected AI voice cloning to imper...

View Case Study
AI Voice Clone Stole $66,000 in Closing Funds from West Michigan Couple
voice cloning

AI Voice Clone Stole $66,000 in Closing Funds from West Michigan Couple

Brian and Wendy VanDoeselaar of West Michigan lost $66,000 in closing funds after scammers used AI voice cloning to impe...

View Case Study