A fake WhatsApp message and a cloned voice were enough to move 95 million euros out of Italy's biggest bank. More than a third of it is now sitting in crypto wallets nobody can trace. Paolo Molesini was chairman of Fideuram, the private banking arm of Intesa Sanpaolo, when a WhatsApp message landed on his phone in February that appeared to come from Intesa Sanpaolo's actual chief executive, Carlo Messina.
The message described an urgent, time-sensitive overseas opportunity and asked Molesini to push through a series of transfers via Fideuram's treasury. It wasn't Messina. According to Reuters, which cited people familiar with the matter, the message was the opening move in a fraud that would eventually funnel roughly 95 million euros, about 108 million dollars, out of one of Europe's largest banks.
The WhatsApp message alone probably wasn't going to be enough. So the fraudsters followed up with a phone call. The voice on the line belonged, or seemed to, to Paolo Nastasi, the managing partner of A&O Shearman's Italian office, confirming that the transfers were legitimate.
Reuters reported that the callers had used AI tools to clone Nastasi's voice. He never made that call. Between a spoofed executive on text and a cloned lawyer on audio, the scheme had built exactly the kind of second-source confirmation that fraud training usually tells people to look for.
The transfers moved out of Fideuram's treasury and were routed primarily through accounts in China and Hong Kong. Fideuram's own controls eventually caught the activity, and international cooperation between Italian, Chinese and Portuguese authorities clawed back a large share of it. Roughly 59 million euros has been recovered or frozen.
The remaining 36 million euros was converted into cryptocurrency before it could be stopped, and Reuters reported that trail has gone cold. Once money crosses into crypto through a chain of overseas wallets, tracing it becomes a different, much harder problem than freezing a bank wire. Molesini resigned as Fideuram's chairman in March, citing personal reasons.
Reuters did not report that he faces any investigation, and neither he nor other Fideuram executives have been named as suspects. Milan prosecutors have opened a computer fraud investigation into a foreign national believed to be living outside Europe, according to Reuters, though no one has been charged. Here's the thing that should worry every bank security chief reading this: Fideuram is not a small regional lender that skipped its fraud training.
It's the private banking division of Intesa Sanpaolo, a bank with nearly a trillion euros in assets and a compliance apparatus built for exactly this kind of threat. Reuters also reported that Intesa Sanpaolo has logged thousands of AI-generated scam attempts aimed at impersonating its CEO since the start of 2026. This wasn't a one-off.
It's a pattern the bank is actively fighting, and this is the one that got through. Voice cloning used to require minutes of clean audio and real technical effort. It doesn't anymore.
A public interview, an earnings call, a conference panel, any of that is enough source material now, and the tools to turn it into a convincing phone call are cheap and widely available. A senior partner at a major law firm has almost certainly given more than one public interview or recorded call. That's the raw material fraudsters used to impersonate Nastasi, and it's the same raw material available for the next executive at the next bank.
The obvious lesson is that voice on a phone call is no longer proof of identity, and any bank still treating it as a secondary check should stop. Callback verification through numbers already on file, out-of-band confirmation through a separate channel entirely, and internal rules that no single call or message can authorize an overseas transfer of this size, those are the basic fixes. None of them are exotic.
What's changed is the cost of not having them. A fake message and a cloned voice used to be a small-business problem, the kind of thing that hit a single accounts-payable clerk at a mid-sized firm. Now it's a nine-figure problem at a bank most Italians trust with their savings, and there's no reason to think Fideuram will be the last one to find that out.
Also read: An AI agent just beat four doctors at diagnosing emergency room patients • Bill Gates Says AI Is Powerful Enough to Cause a Billion Deaths • UpGuard found 16000 Supabase databases leaking user data to the open web This article is posted in AI News , check it out for more related stories.
Source: Startup Fortune
Live · Daily New



