AI messaging scam losses have now reached the top of Italian banking. Fraudsters stole about €95 million ($108 million) from Fideuram, the private banking arm of Intesa Sanpaolo, Italy’s biggest lender, after posing as the group’s chief executive on WhatsApp and then cloning a lawyer’s voice to confirm the request. Two sources told Reuters on 25 September 2026 that more than half the money has since been recovered, but about €36 million is still missing. The case was first reported that morning by Corriere della Sera.
The AI messaging scam ran in February 2026 and stayed private for seven months. Fideuram’s then-chairman, Paolo Molesini, resigned in March citing personal reasons, and neither Intesa Sanpaolo nor Fideuram has commented. Molesini and the other executives are not under investigation. Milan prosecutors are investigating a single foreign national living outside Europe on suspicion of computer fraud.
This article sets out how the AI messaging scam worked step by step, where the money went and what came back, how the case compares with earlier executive impersonation attacks in Italy and abroad, and which payment controls would have broken the chain. It separates what the sources confirm from what remains unknown.
Table of contents
- How the AI Messaging Scam Unfolded at Fideuram
- Where the AI Messaging Scam Money Went
- AI Messaging Scam Timeline: February to September 2026
- Why the AI Messaging Scam Worked on a Bank
- The AI Messaging Scam Pattern Across Italy and Abroad
- What the AI Messaging Scam Means for Payment Controls
- The AI Messaging Scam in the Wider Fraud Numbers
- What Is Still Unknown About the AI Messaging Scam
- Frequently Asked Questions About the AI Messaging Scam
- References
How the AI Messaging Scam Unfolded at Fideuram
Every account of the AI messaging scam describes the same four moves, and all of them happened, in Corriere’s phrase, within “a handful of hours” in February 2026. No single step was technically sophisticated. The skill was in the sequence, which gave each fake message a second fake message to lean on.
A WhatsApp message from the group chief executive
The AI messaging scam began with a WhatsApp message that Molesini believed came from Carlo Messina, chief executive of the parent company. The fake Messina asked for urgent help with an overseas financial transaction that Intesa did not want to miss. For practical reasons, the message said, the payments had to go through Fideuram’s treasury rather than Intesa’s own.
That detail did a lot of work in the AI messaging scam. It explained why a subsidiary was being asked to move money for its parent, and it put the request on the chairman’s desk rather than in the group’s normal payment channels.
A cloned voice from a real law firm
The second contact was a phone call. The caller appeared to be a senior partner at a prominent international law firm, presented as the intermediary on the deal. Corriere and Il Sole 24 Ore identify the impersonated lawyer as the managing partner of A&O Shearman’s Italian practice, a business lawyer Molesini knew. Both papers stress that he was entirely uninvolved and unaware of the scheme.
The voice sounded exactly like his because, according to Reuters’ sources, the callers used AI to replicate it. The call supplied what the WhatsApp message could not: an independent-seeming voice confirming the instruction. It is also the part of the AI messaging scam that relied on AI.
Emails dressed as the law firm’s
Corriere adds a third channel that the wire reports leave out. In the same narrow window, emails crafted to look as if they came from the law firm delivered the details of the companies and foreign accounts to be paid. The AI messaging scam therefore used chat, voice and email, and each channel appeared to corroborate the others.
Transfers approved by the chairman
Believing the request was genuine, Molesini instructed Fideuram’s finance department to make a series of transfers to foreign accounts. Corriere says the finance director released the payments on the chairman’s instruction, believing he was carrying out a task set by the head of the group. The money went mainly to China and Hong Kong. Some of it later surfaced in Portugal.
| Step | Channel | Who was impersonated | What it achieved |
|---|---|---|---|
| 1 | WhatsApp message | Intesa Sanpaolo CEO Carlo Messina | Urgent request to pay through Fideuram’s treasury |
| 2 | Phone call with an AI-cloned voice | Senior partner at an international law firm | Independent-seeming confirmation of the deal |
| 3 | The same law firm | Beneficiary companies and account details | |
| 4 | Internal instruction | None: the chairman acted in good faith | Finance department sends about €95m abroad |
Where the AI Messaging Scam Money Went
The headline figure for the AI messaging scam is about €95 million sent. The more useful figures are what came back and from where. Fideuram’s response was fast, and it is the reason this story is about a partial loss rather than a total one.
Two recoveries in two countries
According to Corriere, Fideuram’s internal security systems raised the alarm quickly, and the bank activated international interbank cooperation. A bank in China identified, froze and returned €40 million. Separately, Milan prosecutors Alfonso Serritiello and Barbara Benzi, working with colleagues in Lisbon under the auspices of Eurojust, stopped a further €13 million at a bank in Portugal before it could move on. Milan’s preliminary investigations judge Sonia Mancini signed the seizure order in May, L’Unione Sarda reports.
Those two sums add up to the roughly €53 million of AI messaging scam proceeds that Reuters’ sources say was recovered through cooperation between authorities in China, Portugal and Italy.
The part that became cryptocurrency
At least €36 million is still missing. It passed through a network of overseas accounts and was converted into cryptocurrency before it could be traced. Investigators are now sending letters rogatory, formal requests for legal help, to other countries in an attempt to find it before the fraudsters can cash out.
| Flow | Euros | US dollars at $1 = €0.8772 | Share of €95m |
|---|---|---|---|
| Sent abroad, mainly to China and Hong Kong | about €95m | about $108.3m | 100% |
| Frozen and returned by a bank in China | €40m | $45.6m | 42.1% |
| Seized at a bank in Portugal | €13m | $14.8m | 13.7% |
| Missing, converted to cryptocurrency | at least €36m | $41.0m | 37.9% |
| Not accounted for in the reporting | about €6m | $6.8m | 6.3% |
The figures do not quite reconcile
The recovered €53 million plus the missing €36 million comes to €89 million, not €95 million. The difference of about €6 million is not explained in any of the reporting. It may be rounding, since every outlet calls the total approximate and the missing sum “at least” €36 million. Il Sole 24 Ore also notes that some funds were recovered independently as well as through prosecutors. Until Fideuram or the prosecutors publish exact figures, the net loss from the AI messaging scam is best stated as a range of €36 million to €42 million.
Why the recoveries were possible at all
Recoveries from an AI messaging scam depend on speed. Money that is still sitting in a correspondent bank can be frozen with a phone call and a legal request. Money that has been split across mule accounts and swapped into cryptocurrency usually cannot. The difference between the €53 million recovered and the €36 million lost is, in large part, the difference between those two states.
AI Messaging Scam Timeline: February to September 2026
The AI messaging scam took hours to execute and seven months to become public. The dates below come from Corriere, Reuters and L’Unione Sarda.
| Date | Event |
|---|---|
| February 2026 | Fake WhatsApp from the “CEO”, cloned-voice call and forged emails; about €95m transferred within hours |
| February 2026 | Fideuram detects the irregularities, alerts banks and authorities, and files a complaint |
| 12 March 2026 | Molesini resigns as chairman “for personal reasons”; no further explanation is given |
| May 2026 | Judge Sonia Mancini signs a seizure order naming a foreign suspect; €13m frozen in Portugal |
| 25 September 2026 | Corriere della Sera reports the fraud; Reuters confirms it with two sources |
Seven months of silence
When Molesini stepped down, Fideuram issued what Corriere calls an “aseptic” statement citing personal reasons. Nothing public connected the resignation to a nine-figure payment fraud until the newspaper’s report. Keeping quiet while funds are being traced is a defensible investigative choice, because publicity can prompt fraudsters to move money faster. It also means that other banks spent seven months unaware that an AI messaging scam had just worked on one of Italy’s largest institutions.
A suspect who may not exist
According to L’Unione Sarda, the one name in the Milan file has been registered for months and may itself be a fictitious identity, most likely linked to the money movements rather than to whoever ran the operation. The prosecutor’s office, including deputy prosecutor Eugenio Fusco, is pursuing the wider group through international requests.
Why the AI Messaging Scam Worked on a Bank
It is tempting to treat the AI messaging scam as a failure of one person’s judgement. The details point to something more structural. The attack was built around the way authority moves inside a banking group, and each step removed a reason to doubt the one before.
Authority flowed downhill
The message appeared to come from the most senior person in the group and landed with the chairman of a subsidiary. Hierarchy works against verification here. A subsidiary chairman who questions an urgent personal request from the group chief executive is taking a social risk. The attackers knew that, and they also knew that a chairman can instruct a finance department.
The cover story explained its own oddities
Why would Intesa route a payment through Fideuram’s treasury? The message answered that question before it was asked, with “practical reasons” that stopped Intesa acting alone. A good cover story anticipates the obvious objection. This one did.
The confirmation channel was forged too
The standard advice for payment fraud is to confirm through a second channel. Here the second channel was part of the attack. A voice call from a familiar lawyer, followed by email from what looked like the lawyer’s firm, is exactly what a careful person might treat as confirmation. When all the channels are controlled by the attacker, cross-checking between them proves nothing.
Urgency and discretion
Corriere describes the fraud team as “very attentive to psychological profile”. The story combined urgency, a deal at risk, with discretion, a confidential transaction. Those two pressures together discourage the one thing that defeats this kind of fraud: pausing to call the real person on a number you already have.
The amount was large but not absurd
Fideuram administers about €450 billion of client assets, Corriere reports. Measured against that, €95 million is about 0.02%. As the newspaper puts it, the sums were “not epochal” for an institution of that size, though large in absolute terms. An AI messaging scam request that would look outlandish at a small firm can look routine at a large one, and a routine-looking amount attracts less scrutiny.
The AI Messaging Scam Pattern Across Italy and Abroad
Fideuram is by far the largest of the Italian cases Corriere lists, but the AI messaging scam follows a script that has been used against Italian companies for years. Corriere lists earlier victims, and international cases show the same structure with different channels.
| Case | Impersonated | Channels | Outcome |
|---|---|---|---|
| Fideuram (Intesa Sanpaolo), 2026 | Group CEO and a law firm partner | WhatsApp, cloned voice, email | About €95m sent, at least €36m lost |
| Massimo Moratti, 2025 | Italy’s defence minister | Cloned voice | Nearly €1m sent, almost all recovered |
| Maire Tecnimont, earlier years | Not detailed in the reporting | A similar scheme, per Corriere | €18m |
| Sisal, earlier years | Not detailed in the reporting | A similar scheme, per Corriere | €5.5m |
| Ferrari, July 2024 | CEO Benedetto Vigna | WhatsApp, cloned voice | Foiled by a security question |
| Arup (Hong Kong), early 2024 | Chief financial officer and colleagues | Deepfake video call | HK$200m, about $25m, lost |
Ferrari: the same script, a different ending
Ferrari’s near miss in July 2024 reads like a rehearsal for Fideuram. An executive received WhatsApp messages from an unfamiliar number with a profile photo of chief executive Benedetto Vigna, mentioning a big acquisition and a non-disclosure agreement that “our lawyer” would send. A live call followed in a convincing clone of Vigna’s southern Italian accent, about a deal with China-related snags that needed a currency hedge. The executive asked for the title of a book Vigna had recommended a few days earlier. The call ended. Nothing was lost.
Arup: video instead of voice
In early 2024 a finance employee at the engineering group Arup in Hong Kong joined a video call with what appeared to be the chief financial officer and other colleagues. All were deepfakes. The employee paid out HK$200 million, about $25 million. Arup confirmed in May 2024 that fake voices and images were used and said its internal systems were not compromised.
Moratti: a minister’s voice
Reuters recalls that last year fraudsters using AI to mimic the voice of an Italian minister persuaded businessman Massimo Moratti to transfer nearly €1 million to an overseas account. Corriere adds that the pretext was a patriotic appeal to fund the release of two Italian hostages, and that Milan prosecutors returned almost all of it.
What the cases have in common
Every case, like the Fideuram AI messaging scam, uses a senior figure’s authority, a confidential deal and time pressure. What has changed is the quality of the fakes. A cloned voice or a deepfake video removes the tell that used to give these calls away. The AI messaging scam at Fideuram shows that voice cloning is now good enough to fool someone who personally knows the person being impersonated.
What the AI Messaging Scam Means for Payment Controls
The practical lesson of the AI messaging scam is not to spot better fakes. People will keep losing that contest as the fakes improve. The lesson is to design payment approval so that a perfect fake still cannot move money on its own. We have covered the defensive side in deepfake phishing defences and in protecting executives against real-time voice cloning. The controls below apply those ideas to this case.
Call back on a number you already hold
Verification defeats an AI messaging scam only if the verifying channel is one the attacker cannot supply. A call to the chief executive’s known number, or to the law firm’s switchboard from its public website, would have reached the real people. Neither the WhatsApp contact nor the caller’s number should count as verification, however familiar the voice.
Agree challenge questions in advance
Ferrari’s executive defeated a live voice clone with one personal question. Firms can formalise this with pre-agreed challenge phrases for out-of-pattern payment requests between senior people. It sounds old-fashioned. It works because a model trained on public speeches does not know what was said in a private conversation last week.
Apply payment rules to the chairman too
Corriere’s account suggests the finance function executed the transfers because the instruction came from the chairman. Dual approval, payee verification and cooling-off periods should apply to new foreign beneficiaries whoever sends the instruction. Seniority should add review, not skip it.
Treat secrecy plus urgency as the alarm
A request that is both urgent and confidential, arrives outside normal channels and involves new foreign beneficiaries is the fingerprint of an AI messaging scam. Written policy should say that this combination triggers a mandatory pause and escalation, so the person receiving it does not have to find the nerve to question the boss.
Rehearse the recall
Fideuram recovered more than half the money because it moved quickly. A written recall playbook, with correspondent-bank contacts, legal templates and a named owner, turns minutes into recovered funds. Our guide to a business email compromise response plan sets out the first-hour steps. A retained incident response partner helps when the payments have already left.
| Control | Step of the fraud it breaks | Defeated by a better deepfake? |
|---|---|---|
| Callback to a known number | Steps 1 and 2: fake CEO and fake lawyer | No |
| Pre-agreed challenge question | Step 2: cloned-voice call | No, unless the secret leaks |
| Dual approval for new foreign payees | Step 4: the transfers | No |
| Mandatory pause on urgent, confidential requests | The pressure behind all four steps | No |
| Staff awareness of voice cloning | Step 2 | Increasingly, yes |
| Rehearsed recall playbook | Limits the loss after step 4 | No |
The AI Messaging Scam in the Wider Fraud Numbers
Fideuram’s loss is a single case, but it sits inside a category that is already measured in billions. Business email compromise ranked second only to investment fraud by reported losses in the FBI’s 2024 statistics, and regulators have started naming deepfakes in their warnings.
Business email compromise is a multi-billion line
The FBI’s Internet Crime Complaint Center recorded $16.6 billion of reported losses in 2024 across 859,532 complaints, a 33% rise on 2023. Business email compromise alone accounted for $2.77 billion, after $2.95 billion in 2023 and $2.74 billion in 2022. The AI messaging scam at Fideuram belongs to the same family, moved from email into chat and voice.
Speed is also what the FBI relies on
The same report describes IC3’s Recovery Asset Team and its Financial Fraud Kill Chain, which asks receiving banks to freeze funds from fraudulent transfers. Most of the requests it starts concern business email compromise. The approach is the one that saved Fideuram €53 million: report fast, freeze while the money is still in the banking system, and work across borders.
Regulators now name deepfakes explicitly
In November 2024 the US Treasury’s Financial Crimes Enforcement Network issued an alert to help financial institutions identify fraud schemes that use deepfake media created with generative AI tools. It set out red-flag indicators and reminded institutions of their reporting duties. For banks, the Fideuram case moves that warning from a regulatory notice to a named peer’s loss. For most firms, this kind of fraud is a cybersecurity and finance problem at the same time, and it needs owners in both teams.
What Is Still Unknown About the AI Messaging Scam
Much of the AI messaging scam is documented, but several facts that matter for anyone assessing the risk have not been disclosed.
How the voice was cloned
None of the reports says how the lawyer’s voice was obtained or cloned. Senior lawyers often speak at conferences and in recorded interviews, which would give a cloning tool plenty of material. That is inference, not reporting.
Whether the €6 million gap is real
As set out above, the published figures leave about €6 million unexplained. Whether that is rounding, an unreported recovery or an additional loss will only be clear if Fideuram or the prosecutors give exact figures.
What Fideuram changed afterwards
Intesa Sanpaolo and Fideuram declined to comment, so it is not known what payment or verification controls changed after February. Nor is it known whether the case prompted guidance to other Italian banks during the seven months it stayed private.
Who ran it
A single foreign suspect, possibly a false identity, is not an answer. Corriere notes that the money in the Moratti case also went to Hong Kong, as well as the Netherlands. Whether the Fideuram operation connects to earlier Italian cases is for investigators to establish.
Frequently Asked Questions About the AI Messaging Scam
How much did the AI messaging scam cost Intesa?
About €95 million ($108 million) left Fideuram. Roughly €53 million was recovered, and at least €36 million remains missing.
Was anyone at Fideuram charged?
No. Reuters’ sources say neither Molesini nor other Fideuram executives are under investigation. Milan prosecutors are investigating one foreign national living outside Europe.
Did the fraudsters use AI for the WhatsApp message too?
The reports attribute the AI element to the cloned voice on the phone call. The WhatsApp message and emails are described as impersonations, without detail on how they were produced.
Could it happen to a smaller company?
Yes. An AI messaging scam against a smaller firm would involve smaller amounts, but the method needs only a senior person’s public voice recordings, a plausible deal and a finance team that will act on a senior instruction.
References
Reuters (via MSN): AI messaging scam costs Italy’s top bank Intesa millions, sources say
L’Unione Sarda: Fideuram scam using a fake WhatsApp and an AI-engineered voice
Fortune: Ferrari exec foils deepfake plot by asking a question only the CEO could answer
CNN: Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee
The Guardian: UK engineering firm Arup falls victim to deepfake scam
FBI Internet Crime Complaint Center: 2024 Internet Crime Report
FinCEN: Alert on fraud schemes involving deepfake media targeting financial institutions
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.