Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
In February 2026, Paolo Molesini, then chairman of Fideuram, the private banking arm of Italy's largest lender Intesa Sanpaolo, received a WhatsApp message that appeared to come from Intesa's chief executive, Carlo Messina. A phone call followed. The voice on the line belonged, as far as Molesini could tell, to Paolo Nastasi, a senior partner at the Italian office of the law firm A&O Shearman. Neither man had placed either message. Both had been faked with artificial intelligence, and the exchange ended with Fideuram wiring €95 million ($108 million) to accounts in China and Hong Kong.
More than half of that money has since been recovered through a rare piece of international cooperation. Roughly €36 million has not, and the trail on that portion has gone cold. What makes this case worth studying is not the size of the loss. It is that the fraud succeeded by cloning the voice of a real, named professional whose job requires him to speak on the record, then using that stolen voice to walk straight through the verification step banks tell their own staff to rely on.
According to Reuters reporting confirmed by multiple outlets, the scheme opened with a text message on WhatsApp, the messaging app, sent to Molesini and made to look like it came from Messina. The message set up a follow-up call. On that call, a voice matching Nastasi, the A&O Shearman partner, walked Molesini through instructions to move funds abroad as part of what he was led to believe was a confidential, time-sensitive transaction. Nastasi never made the call. Reporting on the case notes that Nastasi, like most senior lawyers who appear at conferences, give press interviews or take part in recorded client calls, has ample public audio available for anyone looking to reproduce his voice. That is very likely where the source material came from, though neither Intesa Sanpaolo nor investigators have confirmed the exact recordings used.
Voice cloning tools of this kind need only a short sample, often under a minute, of a person's real speech to generate new sentences in a voice that colleagues would recognize on a phone line. Combined with a spoofed or convincing WhatsApp identity, the two channels reinforced each other: a familiar name in text, then a familiar voice on the phone, arriving in the sequence a legitimate confidential deal would actually take. Molesini authorized the transfers. Investigators in Milan have since opened a computer fraud case against a foreign national believed to be living outside Europe. Molesini resigned as Fideuram's chairman in March 2026, citing personal reasons. Neither he nor other Fideuram executives face any investigation themselves.
For Fideuram, the concrete cost is €36 million that investigators do not expect to recover, plus a chairman who is no longer in his job. For any finance or executive team, the more useful number is the one this case did not need: no forged document, no hacked account, no malware. Two brief, well-timed conversations were enough, because they exploited the fact that voice and a recognizable name are still treated as identity in most approval processes, even at a bank that presumably trains its own staff on fraud. If your organization's playbook for large or unusual transfers includes a phone call as the final check, that call is now exactly as fake-able as an email, and considerably more convincing to the person receiving it, because hearing a familiar voice bypasses the skepticism that written text usually gets. An FBI advisory on generative AI fraud, issued in December 2024, warned that criminals were already combining synthetic audio and video with social engineering to defeat identity checks. Fideuram is the case that shows what that warning looks like at nine figures. The broader shift is that attackers no longer need to compromise a company's systems at all. They only need enough public audio of the right two people and a plausible reason for those two people to be on the phone together.
Fideuram lost €95 million to two phone-based impersonations that needed no hacking at all, only a voice cloning tool and a handful of public recordings of a real lawyer talking about his real work. The detail worth carrying into your next security meeting is not the size of the loss. It is that the verification step your team already trusts, a familiar voice on a phone call, is the one this attack was built to pass.

