Fideuram, the private banking arm of Italy's largest lender Intesa Sanpaolo, was defrauded of roughly €95 million in a scheme that used an AI-cloned voice, according to insiders cited by Reuters and first reported by Corriere della Sera. More than half of the money was later recovered.

The sequence, as described to Reuters, began in February with a WhatsApp message that appeared to come from Intesa Sanpaolo chief executive Carlo Messina, asking Paolo Molesini — then chairman of Fideuram — for urgent help with a foreign transaction. A phone call followed, apparently from a senior partner at a well-known law firm, confirming the instruction. The callers used AI to imitate the lawyer's voice. Believing the request genuine, Molesini instructed his finance department to make transfers to accounts mainly in China and Hong Kong.

Fideuram discovered the irregularities and alerted authorities in several countries. Cooperation between investigators in China, Portugal and Italy allowed a large part of the funds to be secured; the remainder was moved through a network of foreign accounts and converted into cryptocurrency. Total damage is put at €95 million.

Molesini stepped down in March, citing personal reasons; insiders say neither he nor other Fideuram executives are under investigation. Milan's public prosecutor's office is investigating a foreign national living outside Europe on suspicion of computer fraud. According to the Reuters report, it is not clear from the available information how the use of AI was established.

It is not the first case of its kind in Italy: last year, fraudsters used an AI-imitated voice of an Italian minister to persuade a businessman to transfer almost €1 million, which was recovered. The better-known precedent remains the 2024 Arup incident in Hong Kong, where an employee was deceived into paying out around $25 million after a video call populated by deepfaked colleagues.

The Fideuram case raises a question the industry has mostly answered with process rather than technology: at a large bank, a single executive's instruction can still move nine-figure sums. Voice biometrics, callback verification over a second channel and dual authorisation for high-value outbound transfers are the controls that would have to fail — and here they evidently did.