In a shocking incident, Italian bank Fideuram, a subsidiary of Intesa Sanpaolo, one of Italy's major banking groups, was duped out of approximately €95 million in a sophisticated scam. The scammers used AI-generated documents, fake messages, and voice cloning to deceive the bank's officials. The scam came to light in February 2026 when Paolo Molesini, then president of Fideuram, received a WhatsApp message purportedly from Carlo Messina, the CEO of Intesa Sanpaolo.

The scammers, posing as officials from Intesa Sanpaolo, convinced Molesini to facilitate a financial transaction. To add authenticity to their claims, they even cloned the voice of Paolo Nastasi, an associate lawyer from the A&O Shearman law firm in Italy, during a phone conversation. Unbeknownst to Molesini, Nastasi was not involved in the transaction. The scammers created fake payment instructions and documents to support their scheme, which involved multiple transfers to accounts in Portugal, Hong Kong, and China.

The scammers' modus operandi involved creating a web of deceit, using AI-powered tools to generate convincing documents and fake messages. They also used voice cloning to impersonate trusted individuals, making it difficult for Molesini to verify the authenticity of the requests. The bank's officials, trusting the authenticity of the messages and voice, proceeded with the transactions, ultimately transferring approximately €95 million to the scammers' accounts.

The scam was uncovered after the transactions were completed, prompting an investigation by Italian authorities. Fortunately, a significant portion of the funds was recovered, with around €13 million seized from a Portuguese account and over €40 million blocked in China. However, approximately €36 million remains unaccounted for, with some of the funds reportedly converted into cryptocurrencies.

This incident highlights the growing threat of AI-powered scams, which can be used to deceive even the most vigilant individuals. The use of AI-generated documents, voice cloning, and fake messages has made it increasingly difficult to distinguish between genuine and fake requests. As a result, financial institutions and individuals must be cautious when receiving requests, especially those involving large transactions.

The Fideuram incident demonstrates the evolving nature of cybercrime, where scammers no longer need to directly access a bank's computer systems to steal funds. With the advancements in AI technology, scammers can now use social engineering tactics to deceive individuals and gain their trust. This incident serves as a warning to financial institutions and individuals to be vigilant and implement robust security measures to prevent such scams.

The Italian authorities are continuing their investigation into the scam, and it is likely that more information will come to light as the probe progresses. In the meantime, financial institutions and individuals must remain alert to the threat of AI-powered scams and take steps to protect themselves from such attacks. The incident also underscores the need for greater awareness and education on the risks associated with AI-powered scams and the importance of verifying the authenticity of requests.

Key points

  • The scam involved the use of AI-generated documents, fake messages, and voice cloning to deceive Fideuram officials.
  • Approximately €95 million was transferred to the scammers' accounts, with a significant portion recovered by Italian authorities.
  • The incident highlights the growing threat of AI-powered scams and the need for financial institutions and individuals to be vigilant and implement robust security measures.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.