Cybercriminals executed an elaborate AI scam targeting Fideuram, Italy's premier private banking institution, using deepfake voice technology and fake WhatsApp messages to impersonate senior executives. The AI-powered deepfake scam resulted in €95 million being transferred to overseas accounts, with €42 million still missing after conversion to cryptocurrency.

AI-Powered Deepfake Scam Targets Italian Banking Executive

An elaborate AI scam has cost Fideuram, the private banking arm of Intesa Sanpaolo, approximately €95 million ($108 million) after cybercriminals used AI voice clone technology and a fake WhatsApp message to deceive its chairman into authorizing fraudulent overseas transfers

1

. The incident, which unfolded in February 2026, represents one of the most sophisticated cases of AI-driven social engineering targeting the financial sector to date.

Paolo Molesini, who served as chairman of Fideuram at the time, became the primary target of this financial fraud scheme. The attack began when Molesini received what appeared to be a legitimate WhatsApp message from Carlo Messina, CEO of Intesa Sanpaolo, Italy's largest bank

1

. The message requested assistance with an urgent overseas transaction, setting the stage for the AI-generated heist that would follow.

Source: TechSpot

Source: TechSpot

How the AI-Enabled Cybercrime Unfolded

The sophistication of this AI-powered deepfake scam extended beyond simple text messages. After the initial WhatsApp contact, Molesini received a phone call from someone claiming to be a senior partner at a prominent law firm

1

. Sources confirmed that cybercriminals deployed AI models to create a deepfake voice that perfectly mimicked the lawyer's speech patterns, convincing Molesini that the request was authentic and had indeed originated from his superior at Intesa Sanpaolo

2

.

This multi-layered approach to social engineering proved devastatingly effective. Believing the instructions were legitimate, Molesini coordinated with Fideuram's finance department to execute a series of fund transfer operations. The bank wired €95 million to multiple accounts in foreign countries, with the majority of funds flowing to mainland China and Hong Kong

1

2

.

Recovery Efforts and Remaining Losses

Fideuram's security team detected anomalies in the transactions relatively quickly and immediately alerted the receiving banks. Through coordinated efforts involving law enforcement and banking institutions across Italy, Portugal, and China, Fideuram managed to recover €53 million from the fraudulent transactions

1

. However, approximately €42 million remains unaccounted for after passing through a complex network of overseas accounts and ultimately being converted into an undisclosed cryptocurrency

1

.

The scale of this financial fraud is particularly significant given Fideuram's profile. As a private banking institution managing approximately $513.25 billion in assets under management (AUM) and serving high-net-worth clients through more than 7,100 private bankers, Fideuram represents a prime target for sophisticated cybercriminals

2

.

Executive Fallout and Investigation Status

Paolo Molesini resigned from his position as chairman in March 2026, just one month after the AI scam occurred, citing "personal reasons" without providing specific details

2

. The timing of his departure strongly suggests a connection to the fraudulent incident, though neither Molesini nor any other Fideuram executives are currently under investigation

2

.

Milan-based prosecutors are actively working to identify the cybercriminals behind this AI-generated heist. According to reports, one foreign national living outside the European Union is under investigation for computer fraud

1

.

Source: TechRadar

Source: TechRadar

Evolution of Business Email Compromise in the AI Era

This incident represents a dramatic evolution of traditional Business Email Compromise (BEC) attacks. In the pre-AI era, scammers would compromise or spoof executive email addresses to instruct finance departments to execute wire transfers under the guise of confidential business operations

2

. The advent of artificial intelligence has transformed these attacks, enabling criminals to create convincing deepfake voice clones, manipulate instant messaging platforms, and conduct multi-channel social engineering campaigns that are increasingly difficult to detect.

This isn't an isolated incident. Last year, scammers used artificial intelligence to create a deepfake voice of an Italian minister, successfully tricking businessman Massimo Moratti into transferring approximately $1.13 million to an overseas account, though that money was later recovered

2

.

What Financial Institutions Should Watch For

The Fideuram case signals a troubling trend that financial institutions worldwide must prepare for. As AI models continue advancing in sophistication, the barrier to executing convincing voice and video impersonations drops significantly. Organizations should implement multi-factor verification protocols for large fund transfers, establish out-of-band confirmation procedures that use different communication channels, and train executives to recognize red flags even when communications appear authentic. The cryptocurrency conversion aspect also highlights how traditional banking recovery mechanisms become ineffective once funds enter decentralized financial systems, making prevention rather than recovery the critical focus for protecting against AI-enabled cybercrime.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved