- Home
- News Desk
- Case Studies
- AI Voice Clone and Fake WhatsApp Message Cost Italian Bank €95 Million
AI Voice Clone and Fake WhatsApp Message Cost Italian Bank €95 Million
Fraudsters impersonated Intesa Sanpaolo CEO Carlo Messina through a fake WhatsApp message to Fideuram Chairman Paolo Molesini, then reinforced the deception with an AI-cloned phone call posing as a senior law firm partner. Molesini authorized a series of overseas wire transfers totaling €95 million to accounts in China and Hong Kong. The bank later detected anomalies, recovered approximately €53 million through international cooperation, and launched a criminal investigation, while roughly €36 million converted to cryptocurrency remains missing.
By Jesse Seaver, Co-Founder, Trust Onion
Published September 29, 2026
Filed to the News Desk · ai phone call
Originally reported by TechSpot · Read the original article
Part of our Voice Cloning Scams topic guide.
Definitions: Voice clone scam, AI voice cloning, Deepfake scam, Impersonation scam, CEO fraud / executive voice fraud
Analysis of This Incident
How a Cloned Voice Moved €95 Million Out of an Italian Bank →Timeline of Events
The Setup
Fraudsters researched the organizational relationship between Intesa Sanpaolo CEO Carlo Messina and Fideuram Chairman Paolo Molesini, gathering enough detail to craft a credible impersonation via WhatsApp. They also prepared an AI voice clone capable of simulating a senior law firm partner to provide authoritative reinforcement for the transfer requests.
The Attack
Molesini received a WhatsApp message purportedly from CEO Carlo Messina directing him to cooperate with an urgent financial matter. A follow-up phone call using an AI-cloned voice impersonating a senior law firm partner then provided apparent legal cover, instructing Molesini to authorize a series of wire transfers totaling €95 million to accounts in China and Hong Kong. Molesini passed the instructions to Fideuram's finance department, which executed the transfers.
The Impact
Ninety-five million euros left Fideuram's accounts and were routed to overseas destinations. Approximately €36 million was rapidly converted into cryptocurrency, making recovery extremely difficult.
The Discovery
Fideuram's internal systems detected transaction anomalies following the transfers. The bank initiated an internal review and engaged law enforcement, triggering an international effort to trace and freeze the funds.
The Fallout
International cooperation allowed authorities to recover approximately €53 million. Roughly €36 million converted to cryptocurrency remains unaccounted for. Molesini resigned from the chairmanship. Milan prosecutors placed at least one foreign national under investigation for computer fraud.
Attack Details
The attack combined two separate impersonation vectors to maximize credibility and pressure. First, fraudsters sent Fideuram Chairman Paolo Molesini a WhatsApp message crafted to appear as if it came from Intesa Sanpaolo CEO Carlo Messina. The message established the premise of an urgent, confidential financial matter and primed Molesini to expect further contact from a trusted legal intermediary.
The second vector was a phone call using an AI-generated voice clone designed to sound like a senior partner at a law firm. This caller presented the wire transfers as legally sanctioned and time-sensitive, providing the apparent institutional authority needed to move Molesini from passive recipient of a message to active participant in authorizing transfers. A message from a known superior, followed by a call from a credible professional, made the request appear legitimate across two independent channels.
Molesini relayed the instructions to Fideuram's finance department, which processed the transfers without a separate verification step capable of confirming the original executive's identity. Funds totaling €95 million were sent to accounts in China and Hong Kong, jurisdictions that added friction to any subsequent recovery effort.
Approximately €36 million was converted to cryptocurrency quickly, reflecting a deliberate laundering strategy. Once converted, those funds became substantially harder to trace, freeze, or repatriate, and they remain missing. The remaining approximately €53 million was recoverable only through urgent international law enforcement coordination, an outcome that is far from guaranteed in similar incidents.
How Trust Onion Helps
Our analysis — prevention guidance, not part of the reported facts
Before authorizing any wire transfer, a finance team member who challenges an executive instruction with 'What are the words?' would have immediately exposed both layers of this attack. The real Carlo Messina would have known Fideuram's current three codewords. An impersonator sending a WhatsApp message cannot know them. The real law firm partner on the follow-up call would also need to supply the current codewords to be treated as a verified participant in any high-value authorization chain. Neither fraudster could have answered correctly, and the transfer process would have stopped before a single euro moved.
Trust Onion's rotating codewords change every 60 seconds and are calculated locally on each authorized device. There is no server to breach, no database to steal, and no way for an outside party to intercept the current words. A finance team protocol that requires any wire transfer request above a defined threshold to be verbally challenged, regardless of the apparent sender's seniority or the urgency of the request, turns a three-second question into an unbreakable verification step.
In this incident, Molesini received instructions across two channels and treated each as mutually reinforcing confirmation. A codeword protocol breaks that logic entirely. Multi-channel contact from someone who cannot supply the current three words is not confirmation of identity. It is evidence of an impersonation attempt.
Impact Assessment
The direct financial loss was €95 million in outbound wire transfers. International cooperation recovered approximately €53 million, leaving a net unrecovered loss of roughly €36 million that was converted to cryptocurrency and remains outside reach. The speed of the laundering operation shows that the attackers planned their exit strategy in advance and executed it before detection was possible.
Beyond the financial figures, the incident caused serious governance damage. Chairman Paolo Molesini resigned, removing a senior executive from one of Italy's largest private banking groups and creating leadership uncertainty at a time when the institution was also managing a public fraud disclosure. The reputational cost to Fideuram and its parent, Intesa Sanpaolo, extended to client confidence in the bank's internal authorization controls.
The criminal investigation by Milan prosecutors, which has placed at least one foreign national under scrutiny for computer fraud, signals a protracted legal process. Regulatory scrutiny of the bank's internal transfer approval procedures is a probable consequence, along with potential remediation costs and enhanced compliance obligations.
Cite this page
AI Voice Clone and Fake WhatsApp Message Cost Italian Bank €95 Million — Trust Onion, September 29, 2026. https://trustonion.io/case-studies/ai-voice-clone-and-fake-whatsapp-message-cost-italian-bank-95-million
Lessons Learned
Multi-channel contact, such as a WhatsApp message followed by a phone call, does not constitute independent verification. Both channels can be simultaneously spoofed by a coordinated fraud operation.
AI voice cloning can convincingly replicate executives and trusted third parties. Vocal familiarity is no longer a reliable authentication signal for high-value authorizations.
A mandatory verbal codeword challenge before any wire transfer authorization gives finance teams a zero-cost, technology-agnostic verification layer that voice cloning cannot defeat.
Cryptocurrency conversion is a deliberate exit strategy. Funds moved to crypto within hours of a fraudulent transfer become substantially unrecoverable, making prevention the only reliable defense.
Executive impersonation fraud carries governance consequences beyond direct financial loss, including leadership departures, criminal investigations, and regulatory scrutiny of internal controls.
Key Takeaways
Fraudsters used a fake WhatsApp message and an AI-cloned voice call to authorize €95 million in wire transfers from Italian private bank Fideuram in September 2026.
Approximately €36 million was converted to cryptocurrency within hours of the transfers and remains unrecovered despite international law enforcement cooperation.
Fideuram Chairman Paolo Molesini resigned following the incident, and Milan prosecutors opened a computer fraud investigation targeting at least one foreign national.
The attack succeeded because two spoofed channels, a text message and a phone call, were each treated as independent confirmation of the same fraudulent instruction.
A mandatory three-word codeword challenge on executive wire-transfer requests costs nothing and cannot be defeated by AI voice cloning or message spoofing.
Frequently Asked Questions
What happened in the Fideuram AI voice clone fraud?
Fraudsters sent Fideuram Chairman Paolo Molesini a WhatsApp message impersonating Intesa Sanpaolo CEO Carlo Messina, then followed up with an AI-cloned phone call posing as a senior law firm partner. Molesini authorized a series of overseas wire transfers totaling €95 million to accounts in China and Hong Kong. The bank detected anomalies, and international cooperation recovered approximately €53 million, but roughly €36 million converted to cryptocurrency remains missing.
How much money was lost in the Fideuram fraud?
Ninety-five million euros was transferred out of Fideuram. Approximately €53 million was recovered through international law enforcement cooperation. Roughly €36 million was converted to cryptocurrency and has not been recovered.
How could this wire transfer fraud have been prevented?
A mandatory codeword verification protocol would have stopped this attack before any funds moved. If Molesini or anyone in the finance department had asked the caller, 'What are the words?', neither the WhatsApp impersonator nor the AI-cloned voice on the follow-up call could have supplied Fideuram's current three codewords. Trust Onion's rotating words change every 60 seconds, are calculated locally on authorized devices, and give finance teams a zero-cost challenge that AI voice cloning cannot defeat. The real CEO knows the words. An impersonator does not.
Why was the fraudulent wire transfer difficult to reverse?
The funds were sent to accounts in China and Hong Kong, jurisdictions that require international legal coordination to freeze or recover assets. Approximately €36 million was rapidly converted to cryptocurrency after arrival, a deliberate step that places funds outside the conventional banking system and makes recovery extremely difficult. Only approximately €53 million was reachable through international cooperation.
What verification step should finance teams add to prevent CEO fraud?
Finance teams should require any executive requesting a wire transfer to verbally supply the current three rotating codewords before the request is actioned. This challenge applies regardless of the request's apparent source, the number of channels used to deliver it, or the urgency claimed by the requester. Trust Onion provides this rotating codeword system free of charge. The words rotate every 60 seconds, work without an internet connection, and cannot be cloned or intercepted.
More case studies
Michigan Couple Loses $66,000 in Real Estate Voice-Cloning Scam
Michigan homebuyers identified as the VanDoeselaars lost $66,000 after scammers used suspected AI voice cloning to imper...
AI Voice Clone Stole $66,000 in Closing Funds from West Michigan Couple
Brian and Wendy VanDoeselaar of West Michigan lost $66,000 in closing funds after scammers used AI voice cloning to impe...
Scotch Plains Resident Loses $3,000+ in Family Impersonation Scam
In September 2026, a Scotch Plains, New Jersey resident lost more than $3,000 after fraudsters impersonated a family mem...


