News
FRAUD
AI
news image Published on : 29/09/2026

AI voice clones and fake WhatsApps: Italian banks authorised €121 million in three linked FRAUDS

Italian lenders have been hit by a cluster of sophisticated frauds in which criminals used AI voice cloning, fake WhatsApp messages and forged emails to impersonate senior executives and trusted lawyers.

Fraudsters did not need to breach the banks’ systems.

  • Fraudsters cloned voices, spoofed WhatsApp accounts and forged emails that looked as if they came from people the victims already trusted.

  • In three cases now being investigated in Milan, Italian lenders authorised transfers of about €95 million, €24 million and €2 million — more than €120 million in total.

  • Large sums have been clawed back. Tens of millions have not.

  • Across three cases now under investigation by Milan prosecutors, banks authorised transfers totalling about €121 million.

  • Substantial sums have been recovered through international co-operation, but tens of millions remain missing, some of it converted into cryptocurrency.

Fideuram, the private-banking arm of Intesa Sanpaolo

  • The largest case struck Fideuram, the private-banking arm of Intesa Sanpaolo. In February 2026, then-chairman Paolo Molesini received a WhatsApp message that appeared to come from Intesa chief executive Carlo Messina.

    • The message requested urgent overseas transfers through Fideuram’s treasury, framed as part of a confidential acquisition.

    • A follow-up call used an AI-cloned voice of Paolo Nastasi, a real managing partner at A&O Shearman Italy who had no involvement and was unaware of the plot.

    • Fake documents and emails completed the picture.

    • Molesini authorised a series of transfers totalling about €95 million, mainly to accounts in China and Hong Kong.

  • Fideuram spotted irregularities quickly and triggered emergency procedures.

  • Authorities in China froze and returned around €40 million; a further €13 million was seized in Portugal via Eurojust co-operation with Italian prosecutors.

  • Sources and Italian reporting put recovered funds in the €53–59 million range.

  • Roughly €36–39.5 million remains unaccounted for after the money moved through further overseas accounts and into crypto.

  • Neither Molesini nor other Fideuram executives are under investigation. He resigned as chairman in March, citing personal reasons.

  • Milan prosecutors have registered a foreign IT specialist (described in some reports as Israeli, though the identity may be fictitious) as a suspect for aggravated computer fraud.

  • Intesa Sanpaolo and Fideuram have declined to comment.

Banca Ifis, a specialised lender,

  • A similar pattern hit Banca Ifis, a specialised lender, in May 2026.

  • A manager authorised operations worth about €24 million after a sequence of emails and communications that prosecutors say followed the same playbook of impersonation and voice cloning.

  • Funds were routed through Singapore, Hong Kong, Bahrain and Spain.

  • About €20 million has been recovered, including a seizure in Barcelona. Around €4 million is still outstanding.

Unnamed co-operative bank (a BCC)

  • The third case involves a smaller, unnamed co-operative bank (a BCC). Transfers of about €2 million were authorised under a comparable scheme. Part of the money was later located and recovered in Croatia.

  • Milan prosecutors have opened at least three related files.

  • They describe a method that no longer requires hacking core systems: criminals exploit hierarchy, urgency and now high-quality synthetic voices. Voice cloning of people the victims already knew — a group CEO in one case, a familiar lawyer in another — supplied the verification step that traditional “CEO fraud” emails often lack.

2025 businessman Massimo Moratti

  • The cases sit in a wider Italian pattern.

  • In 2025, fraudsters used an AI imitation of Defence Minister Guido Crosetto’s voice to extract nearly €1 million from businessman Massimo Moratti; that money was later frozen in the Netherlands.

Warning

  • Banks and prosecutors have warned that internal controls built for email spoofing are insufficient when the voice on the line matches someone the recipient trusts.

Notes

  • Net losses after recoveries are lower than the headline transfer totals. Even so, the episode shows how quickly AI-assisted social engineering can move nine-figure sums out of well-resourced institutions before alarms fire.

  • Figures for recovered versus missing sums vary slightly across reports (€53m vs €59m recovered on the Fideuram case; €36m vs €39.5m still out). The ranges above reflect that inconsistency rather than a single official bank disclosure.

Sources (full URLs):
https://www.reuters.com/legal/government/ai-messaging-scam-costs-italys-top-bank-intesa-millions-sources-say-2026-09-25/
https://www.ilsole24ore.com/art/l-ex-capo-fideuram-truffato-whatsapp-e-ia-spariti-36-milioni-AJXuauOB
https://www.lastampa.it/cronaca/2026/09/25/news/fideuram_truffa_36_milioni_whatsapp_voce_clonata_ai_molesini-15748791/
https://www.ansa.it/sito/notizie/cronaca/2026/09/25/i-pm-milano-indagano-su-altre-due-truffe-a-banche-con-ia-una-da-24-milioni_4ea49569-2968-4fc8-9a4e-dfd277f0b8f6.html
https://www.ilgiornaleditalia.it/news/mondo-imprese/824369/banca-ifis-recuperati-20-dei-24-milioni-di-euro-sottratti-con-la-truffa-del-ceo-a-fideuram-mancano-39-5-mln-su-circa-95-mln.html
https://www.heise.de/en/news/AI-enables-million-euro-fraud-at-Italian-bank-11468915.html

FRAUD AI

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.  

Archived News

To find our older articles, please click here.

View archive