top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Deepfake audio and spoofed messages trick Italian private bank into wiring €95 million overseas

Marijan Hassan - Tech Journalist
8 hours ago
2 min read

An elaborate social engineering scheme utilizing artificial intelligence voice cloning and spoofed mobile messaging has defrauded Fideuram - the private banking arm of Italy’s largest financial institution, Intesa Sanpaolo - out of approximately €95 million ($103 million).



The attack represents one of the largest synthetic media financial heists recorded to date, illustrating the expanding vulnerability of corporate payment authorization processes to AI-driven impersonation.


Dual-Layer Social Engineering Targets Senior Executive

According to investigative findings by Milan prosecutors and international law enforcement agencies, the incident unfolded when then-Fideuram Chairman Paolo Molesini received a series of urgent WhatsApp messages purporting to come from Carlo Messina, Chief Executive Officer of the parent group Intesa Sanpaolo.


The spoofed text established an immediate pretext regarding a sensitive, confidential cross-border transaction. Shortly after, the chairman received a phone call featuring a synthetic voice clone mimicking prominent Italian attorney Paolo Nastasi, who reinforced the fake CEO's instructions and provided specific wiring details.


Believing he was acting on verified executive orders, Molesini directed Fideuram’s internal finance department to execute multiple high-value international wire transfers. The funds were dispatched across offshore banking accounts located in mainland China, Hong Kong, and additional overseas jurisdictions.


While neither Molesini nor other bank staff are under criminal investigation, the chairman resigned from his post shortly after the breach was identified.


Multi-Jurisdictional Asset Recovery and Crypto Conversion

Following the discovery of the fraud, Italian authorities initiated emergency asset-tracing operations alongside law enforcement in Portugal, China, and Hong Kong:


Coordinated banking freezes and legal interventions clawed back approximately €40 million from destination accounts, while Portuguese authorities separately froze another €13 million.


However, despite partial recovery efforts totaling €53 million, attackers routed at least €36 million through secondary international transfers and converted the proceeds into privacy-focused digital assets and cryptocurrencies.


Milan prosecutors are currently tracking the remaining digital asset trail while actively investigating a foreign national residing outside Europe in connection with the cyber fraud operation.

 

Catalyzing Defensive Upgrades in European Private Banking

The Fideuram compromise closely follows high-profile deepfake incidents across Asia and Europe, including the $25 million deepfake video call scam targeting engineering giant Arup.


The scale of the €95 million theft is accelerating pressure across European wealth management and private banking sectors to phase out informal communication channels for payment authorizations. Financial institutions across the European Union are increasingly mandating hardware-token approvals, biometric liveness checks, and real-time deepfake voice detection software to insulate corporate finance teams against synthetic identity threats.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page