AI messaging scam losses have now reached the top of Italian banking. Fraudsters stole about €95 million ($108 million) from Fideuram, the private banking arm of Intesa Sanpaolo, Italy’s biggest lender, after posing as the group’s chief executive on WhatsApp and then cloning a lawyer’s voice to confirm the request. Two sources told Reuters on 25 September 2026 that more than half the money has since been recovered, but about €36 million is still missing. The case was first reported that morning by Corriere della Sera.

The AI messaging scam ran in February 2026 and stayed private for seven months. Fideuram’s then-chairman, Paolo Molesini, resigned in March citing personal reasons, and neither Intesa Sanpaolo nor Fideuram has commented. Molesini and the other executives are not under investigation. Milan prosecutors are investigating a single foreign national living outside Europe on suspicion of computer fraud.

This article sets out how the AI messaging scam worked step by step, where the money went and what came back, how the case compares with earlier executive impersonation attacks in Italy and abroad, and which payment controls would have broken the chain. It separates what the sources confirm from what remains unknown.

How the AI Messaging Scam Unfolded at Fideuram

ai messaging scam intesa fideuram cloned voice b smartphone lying flat with a raised card

Every account of the AI messaging scam describes the same four moves, and all of them happened, in Corriere’s phrase, within “a handful of hours” in February 2026. No single step was technically sophisticated. The skill was in the sequence, which gave each fake message a second fake message to lean on.

A WhatsApp message from the group chief executive

The AI messaging scam began with a WhatsApp message that Molesini believed came from Carlo Messina, chief executive of the parent company. The fake Messina asked for urgent help with an overseas financial transaction that Intesa did not want to miss. For practical reasons, the message said, the payments had to go through Fideuram’s treasury rather than Intesa’s own.

That detail did a lot of work in the AI messaging scam. It explained why a subsidiary was being asked to move money for its parent, and it put the request on the chairman’s desk rather than in the group’s normal payment channels.

A cloned voice from a real law firm

The second contact was a phone call. The caller appeared to be a senior partner at a prominent international law firm, presented as the intermediary on the deal. Corriere and Il Sole 24 Ore identify the impersonated lawyer as the managing partner of A&O Shearman’s Italian practice, a business lawyer Molesini knew. Both papers stress that he was entirely uninvolved and unaware of the scheme.

The voice sounded exactly like his because, according to Reuters’ sources, the callers used AI to replicate it. The call supplied what the WhatsApp message could not: an independent-seeming voice confirming the instruction. It is also the part of the AI messaging scam that relied on AI.

Emails dressed as the law firm’s

Corriere adds a third channel that the wire reports leave out. In the same narrow window, emails crafted to look as if they came from the law firm delivered the details of the companies and foreign accounts to be paid. The AI messaging scam therefore used chat, voice and email, and each channel appeared to corroborate the others.

Transfers approved by the chairman

Believing the request was genuine, Molesini instructed Fideuram’s finance department to make a series of transfers to foreign accounts. Corriere says the finance director released the payments on the chairman’s instruction, believing he was carrying out a task set by the head of the group. The money went mainly to China and Hong Kong. Some of it later surfaced in Portugal.

StepChannelWho was impersonatedWhat it achieved
1WhatsApp messageIntesa Sanpaolo CEO Carlo MessinaUrgent request to pay through Fideuram’s treasury
2Phone call with an AI-cloned voiceSenior partner at an international law firmIndependent-seeming confirmation of the deal
3EmailThe same law firmBeneficiary companies and account details
4Internal instructionNone: the chairman acted in good faithFinance department sends about €95m abroad

Where the AI Messaging Scam Money Went

ai messaging scam intesa fideuram cloned voice c microphone on a round weighted stand

The headline figure for the AI messaging scam is about €95 million sent. The more useful figures are what came back and from where. Fideuram’s response was fast, and it is the reason this story is about a partial loss rather than a total one.

Two recoveries in two countries

According to Corriere, Fideuram’s internal security systems raised the alarm quickly, and the bank activated international interbank cooperation. A bank in China identified, froze and returned €40 million. Separately, Milan prosecutors Alfonso Serritiello and Barbara Benzi, working with colleagues in Lisbon under the auspices of Eurojust, stopped a further €13 million at a bank in Portugal before it could move on. Milan’s preliminary investigations judge Sonia Mancini signed the seizure order in May, L’Unione Sarda reports.

Those two sums add up to the roughly €53 million of AI messaging scam proceeds that Reuters’ sources say was recovered through cooperation between authorities in China, Portugal and Italy.

The part that became cryptocurrency

At least €36 million is still missing. It passed through a network of overseas accounts and was converted into cryptocurrency before it could be traced. Investigators are now sending letters rogatory, formal requests for legal help, to other countries in an attempt to find it before the fraudsters can cash out.

FlowEurosUS dollars at $1 = €0.8772Share of €95m
Sent abroad, mainly to China and Hong Kongabout €95mabout $108.3m100%
Frozen and returned by a bank in China€40m$45.6m42.1%
Seized at a bank in Portugal€13m$14.8m13.7%
Missing, converted to cryptocurrencyat least €36m$41.0m37.9%
Not accounted for in the reportingabout €6m$6.8m6.3%
Where the roughly €95 million ended up, as a share of the total sent
Returned by a bank in China €40m, 42.1%
Still missing, converted to cryptocurrency €36m, 37.9%
Seized in Portugal €13m, 13.7%
Gap between the reported figures €6m, 6.3%
Each bar is the reported sum divided by the approximate €95m total. The gap is €95m minus €40m, €13m and €36m.

The figures do not quite reconcile

The recovered €53 million plus the missing €36 million comes to €89 million, not €95 million. The difference of about €6 million is not explained in any of the reporting. It may be rounding, since every outlet calls the total approximate and the missing sum “at least” €36 million. Il Sole 24 Ore also notes that some funds were recovered independently as well as through prosecutors. Until Fideuram or the prosecutors publish exact figures, the net loss from the AI messaging scam is best stated as a range of €36 million to €42 million.

Why the recoveries were possible at all

Recoveries from an AI messaging scam depend on speed. Money that is still sitting in a correspondent bank can be frozen with a phone call and a legal request. Money that has been split across mule accounts and swapped into cryptocurrency usually cannot. The difference between the €53 million recovered and the €36 million lost is, in large part, the difference between those two states.

AI Messaging Scam Timeline: February to September 2026

ai messaging scam intesa fideuram cloned voice d three stacks of coins of different heights

The AI messaging scam took hours to execute and seven months to become public. The dates below come from Corriere, Reuters and L’Unione Sarda.

DateEvent
February 2026Fake WhatsApp from the “CEO”, cloned-voice call and forged emails; about €95m transferred within hours
February 2026Fideuram detects the irregularities, alerts banks and authorities, and files a complaint
12 March 2026Molesini resigns as chairman “for personal reasons”; no further explanation is given
May 2026Judge Sonia Mancini signs a seizure order naming a foreign suspect; €13m frozen in Portugal
25 September 2026Corriere della Sera reports the fraud; Reuters confirms it with two sources

Seven months of silence

When Molesini stepped down, Fideuram issued what Corriere calls an “aseptic” statement citing personal reasons. Nothing public connected the resignation to a nine-figure payment fraud until the newspaper’s report. Keeping quiet while funds are being traced is a defensible investigative choice, because publicity can prompt fraudsters to move money faster. It also means that other banks spent seven months unaware that an AI messaging scam had just worked on one of Italy’s largest institutions.

A suspect who may not exist

According to L’Unione Sarda, the one name in the Milan file has been registered for months and may itself be a fictitious identity, most likely linked to the money movements rather than to whoever ran the operation. The prosecutor’s office, including deputy prosecutor Eugenio Fusco, is pursuing the wider group through international requests.

Why the AI Messaging Scam Worked on a Bank

ai messaging scam intesa fideuram cloned voice e safe box with a round dial

It is tempting to treat the AI messaging scam as a failure of one person’s judgement. The details point to something more structural. The attack was built around the way authority moves inside a banking group, and each step removed a reason to doubt the one before.

Authority flowed downhill

The message appeared to come from the most senior person in the group and landed with the chairman of a subsidiary. Hierarchy works against verification here. A subsidiary chairman who questions an urgent personal request from the group chief executive is taking a social risk. The attackers knew that, and they also knew that a chairman can instruct a finance department.

The cover story explained its own oddities

Why would Intesa route a payment through Fideuram’s treasury? The message answered that question before it was asked, with “practical reasons” that stopped Intesa acting alone. A good cover story anticipates the obvious objection. This one did.

The confirmation channel was forged too

The standard advice for payment fraud is to confirm through a second channel. Here the second channel was part of the attack. A voice call from a familiar lawyer, followed by email from what looked like the lawyer’s firm, is exactly what a careful person might treat as confirmation. When all the channels are controlled by the attacker, cross-checking between them proves nothing.

Urgency and discretion

Corriere describes the fraud team as “very attentive to psychological profile”. The story combined urgency, a deal at risk, with discretion, a confidential transaction. Those two pressures together discourage the one thing that defeats this kind of fraud: pausing to call the real person on a number you already have.

The amount was large but not absurd

Fideuram administers about €450 billion of client assets, Corriere reports. Measured against that, €95 million is about 0.02%. As the newspaper puts it, the sums were “not epochal” for an institution of that size, though large in absolute terms. An AI messaging scam request that would look outlandish at a small firm can look routine at a large one, and a routine-looking amount attracts less scrutiny.

The AI Messaging Scam Pattern Across Italy and Abroad

ai messaging scam intesa fideuram cloned voice f hourglass between two round plates

Fideuram is by far the largest of the Italian cases Corriere lists, but the AI messaging scam follows a script that has been used against Italian companies for years. Corriere lists earlier victims, and international cases show the same structure with different channels.

CaseImpersonatedChannelsOutcome
Fideuram (Intesa Sanpaolo), 2026Group CEO and a law firm partnerWhatsApp, cloned voice, emailAbout €95m sent, at least €36m lost
Massimo Moratti, 2025Italy’s defence ministerCloned voiceNearly €1m sent, almost all recovered
Maire Tecnimont, earlier yearsNot detailed in the reportingA similar scheme, per Corriere€18m
Sisal, earlier yearsNot detailed in the reportingA similar scheme, per Corriere€5.5m
Ferrari, July 2024CEO Benedetto VignaWhatsApp, cloned voiceFoiled by a security question
Arup (Hong Kong), early 2024Chief financial officer and colleaguesDeepfake video callHK$200m, about $25m, lost

Ferrari: the same script, a different ending

Ferrari’s near miss in July 2024 reads like a rehearsal for Fideuram. An executive received WhatsApp messages from an unfamiliar number with a profile photo of chief executive Benedetto Vigna, mentioning a big acquisition and a non-disclosure agreement that “our lawyer” would send. A live call followed in a convincing clone of Vigna’s southern Italian accent, about a deal with China-related snags that needed a currency hedge. The executive asked for the title of a book Vigna had recommended a few days earlier. The call ended. Nothing was lost.

Arup: video instead of voice

In early 2024 a finance employee at the engineering group Arup in Hong Kong joined a video call with what appeared to be the chief financial officer and other colleagues. All were deepfakes. The employee paid out HK$200 million, about $25 million. Arup confirmed in May 2024 that fake voices and images were used and said its internal systems were not compromised.

Moratti: a minister’s voice

Reuters recalls that last year fraudsters using AI to mimic the voice of an Italian minister persuaded businessman Massimo Moratti to transfer nearly €1 million to an overseas account. Corriere adds that the pretext was a patriotic appeal to fund the release of two Italian hostages, and that Milan prosecutors returned almost all of it.

Italian executive impersonation cases named by Corriere, amount taken in euros
Fideuram, 2026 (sent) about €95m
Fideuram, 2026 (still missing) at least €36m
Maire Tecnimont €18m
Sisal €5.5m
Massimo Moratti, 2025 nearly €1m
Bar widths are each amount as a share of Fideuram’s approximate €95m: 36/95 is 38%, 18/95 is 19%, 5.5/95 is 6% and 1/95 is 1%.

What the cases have in common

Every case, like the Fideuram AI messaging scam, uses a senior figure’s authority, a confidential deal and time pressure. What has changed is the quality of the fakes. A cloned voice or a deepfake video removes the tell that used to give these calls away. The AI messaging scam at Fideuram shows that voice cloning is now good enough to fool someone who personally knows the person being impersonated.

What the AI Messaging Scam Means for Payment Controls

The practical lesson of the AI messaging scam is not to spot better fakes. People will keep losing that contest as the fakes improve. The lesson is to design payment approval so that a perfect fake still cannot move money on its own. We have covered the defensive side in deepfake phishing defences and in protecting executives against real-time voice cloning. The controls below apply those ideas to this case.

Call back on a number you already hold

Verification defeats an AI messaging scam only if the verifying channel is one the attacker cannot supply. A call to the chief executive’s known number, or to the law firm’s switchboard from its public website, would have reached the real people. Neither the WhatsApp contact nor the caller’s number should count as verification, however familiar the voice.

Agree challenge questions in advance

Ferrari’s executive defeated a live voice clone with one personal question. Firms can formalise this with pre-agreed challenge phrases for out-of-pattern payment requests between senior people. It sounds old-fashioned. It works because a model trained on public speeches does not know what was said in a private conversation last week.

Apply payment rules to the chairman too

Corriere’s account suggests the finance function executed the transfers because the instruction came from the chairman. Dual approval, payee verification and cooling-off periods should apply to new foreign beneficiaries whoever sends the instruction. Seniority should add review, not skip it.

Treat secrecy plus urgency as the alarm

A request that is both urgent and confidential, arrives outside normal channels and involves new foreign beneficiaries is the fingerprint of an AI messaging scam. Written policy should say that this combination triggers a mandatory pause and escalation, so the person receiving it does not have to find the nerve to question the boss.

Rehearse the recall

Fideuram recovered more than half the money because it moved quickly. A written recall playbook, with correspondent-bank contacts, legal templates and a named owner, turns minutes into recovered funds. Our guide to a business email compromise response plan sets out the first-hour steps. A retained incident response partner helps when the payments have already left.

ControlStep of the fraud it breaksDefeated by a better deepfake?
Callback to a known numberSteps 1 and 2: fake CEO and fake lawyerNo
Pre-agreed challenge questionStep 2: cloned-voice callNo, unless the secret leaks
Dual approval for new foreign payeesStep 4: the transfersNo
Mandatory pause on urgent, confidential requestsThe pressure behind all four stepsNo
Staff awareness of voice cloningStep 2Increasingly, yes
Rehearsed recall playbookLimits the loss after step 4No

The AI Messaging Scam in the Wider Fraud Numbers

Fideuram’s loss is a single case, but it sits inside a category that is already measured in billions. Business email compromise ranked second only to investment fraud by reported losses in the FBI’s 2024 statistics, and regulators have started naming deepfakes in their warnings.

Business email compromise is a multi-billion line

The FBI’s Internet Crime Complaint Center recorded $16.6 billion of reported losses in 2024 across 859,532 complaints, a 33% rise on 2023. Business email compromise alone accounted for $2.77 billion, after $2.95 billion in 2023 and $2.74 billion in 2022. The AI messaging scam at Fideuram belongs to the same family, moved from email into chat and voice.

Business email compromise losses reported to the FBI’s IC3, by year
2022 $2.74bn
2023 $2.95bn
2024 $2.77bn
Bar widths are each year as a share of the 2023 peak: 2.74/2.95 is 93% and 2.77/2.95 is 94%. Source: IC3 2024 annual report.

Speed is also what the FBI relies on

The same report describes IC3’s Recovery Asset Team and its Financial Fraud Kill Chain, which asks receiving banks to freeze funds from fraudulent transfers. Most of the requests it starts concern business email compromise. The approach is the one that saved Fideuram €53 million: report fast, freeze while the money is still in the banking system, and work across borders.

Regulators now name deepfakes explicitly

In November 2024 the US Treasury’s Financial Crimes Enforcement Network issued an alert to help financial institutions identify fraud schemes that use deepfake media created with generative AI tools. It set out red-flag indicators and reminded institutions of their reporting duties. For banks, the Fideuram case moves that warning from a regulatory notice to a named peer’s loss. For most firms, this kind of fraud is a cybersecurity and finance problem at the same time, and it needs owners in both teams.

What Is Still Unknown About the AI Messaging Scam

Much of the AI messaging scam is documented, but several facts that matter for anyone assessing the risk have not been disclosed.

How the voice was cloned

None of the reports says how the lawyer’s voice was obtained or cloned. Senior lawyers often speak at conferences and in recorded interviews, which would give a cloning tool plenty of material. That is inference, not reporting.

Whether the €6 million gap is real

As set out above, the published figures leave about €6 million unexplained. Whether that is rounding, an unreported recovery or an additional loss will only be clear if Fideuram or the prosecutors give exact figures.

What Fideuram changed afterwards

Intesa Sanpaolo and Fideuram declined to comment, so it is not known what payment or verification controls changed after February. Nor is it known whether the case prompted guidance to other Italian banks during the seven months it stayed private.

Who ran it

A single foreign suspect, possibly a false identity, is not an answer. Corriere notes that the money in the Moratti case also went to Hong Kong, as well as the Netherlands. Whether the Fideuram operation connects to earlier Italian cases is for investigators to establish.

Frequently Asked Questions About the AI Messaging Scam

How much did the AI messaging scam cost Intesa?

About €95 million ($108 million) left Fideuram. Roughly €53 million was recovered, and at least €36 million remains missing.

Was anyone at Fideuram charged?

No. Reuters’ sources say neither Molesini nor other Fideuram executives are under investigation. Milan prosecutors are investigating one foreign national living outside Europe.

Did the fraudsters use AI for the WhatsApp message too?

The reports attribute the AI element to the cloned voice on the phone call. The WhatsApp message and emails are described as impersonations, without detail on how they were produced.

Could it happen to a smaller company?

Yes. An AI messaging scam against a smaller firm would involve smaller amounts, but the method needs only a senior person’s public voice recordings, a plausible deal and a finance team that will act on a senior instruction.

References