Deepfake AI Voice Scam: Intesa Loses €95M | Explained

Deepfake AI voice scam cost Italy's Intesa Sanpaolo €95M; €36M missing after conversion to crypto. Here's how the fraud unfolded and what banks should do.

Deepfake AI Voice Scam: Intesa Loses €95M | Explained
Share
Share this article Choose a network or an app on your device.
Email

Edition: EN

Italy's largest bank, Intesa Sanpaolo, has fallen victim to a deepfake AI voice scam that cost its private banking arm Fideuram approximately €95 million, with about €36 million still missing after being converted into cryptocurrency. The fraud began in February 2026 and used AI-cloned voices, fake WhatsApp messages and forged emails to impersonate senior executives and authorize international transfers to China and Hong Kong. Milan prosecutors are investigating the scheme, and Italian justice officials have issued a blunt warning to banks across the country.

What is a deepfake AI voice scam?

A deepfake AI voice scam is a type of fraud in which criminals use generative artificial intelligence to clone a real person's voice and then place phone calls or send voice messages that sound convincingly authentic. Fraudsters need only a few seconds of publicly available audio—from interviews, podcasts or social media—to create a near-identical vocal imitation. The cloned voice is usually paired with urgent requests for wire transfers, account changes or confidential information, making the scam a high-tech evolution of traditional business email compromise (BEC).

What happened at Intesa Sanpaolo?

The case is the latest escalation in deepfake fraud trends that have surged across Europe. According to Italian newspaper Corriere della Sera and sources cited by Reuters, the scheme targeted Fideuram, Intesa Sanpaolo's private banking division. In February 2026, then-Fideuram chairman Paolo Molesini received a WhatsApp message that appeared to come from Intesa CEO Carlo Messina, urgently requesting help with an overseas transaction.

How the Intesa Sanpaolo fraud unfolded

Shortly after the WhatsApp message, Molesini was called by someone posing as Paolo Nastasi, a senior partner at the law firm A&O Shearman Italia. Investigators say the fraudsters used AI voice cloning technology to replicate Nastasi's voice during the call, confirming the transaction request. Fake emails were also sent to reinforce the deception.

Convinced the request was genuine, Molesini instructed the finance department to process a series of transfers totaling roughly €95 million, mainly to accounts in China and Hong Kong. Internal security systems quickly flagged irregularities, and the bank alerted authorities in China, Portugal and Italy.

The financial impact: €95 million lost, €36 million missing

About €40 million was frozen and returned by a Chinese financial institution, and approximately €13 million was seized in Portugal through cooperation coordinated by Eurojust, bringing total recoveries to around €53–59 million. The remaining €36 million remains untraced after being routed through foreign accounts and converted into cryptocurrency, according to sources.

Molesini resigned on 16 March 2026 citing personal reasons; he is not under investigation. Milan prosecutors are now probing a foreign national on suspicion of computer fraud. Intesa Sanpaolo and Fideuram have declined to comment. The missing funds highlight the growing challenge of cryptocurrency laundering schemes in cross-border AI fraud investigations.

Don't think it could never happen to us, Italian justice officials warned banks.

How can banks protect against AI voice fraud?

The Intesa case is not isolated. In 2025, an AI voice scam impersonating Italian Defence Minister Guido Crosetto tricked businessman Massimo Moratti out of nearly €1 million; the funds were later recovered. Moratti later said It all seemed real. According to Gartner, 62% of organizations experienced at least one deepfake attack in the past 12 months, and McAfee reports that 70% of people cannot confidently distinguish a cloned voice from a real one.

Security experts recommend these steps:

  • Verify payment requests through a second, pre-registered channel before releasing funds.
  • Use dual-approval or four-eyes controls for high-value transfers.
  • Train staff to recognize urgency, secrecy and pressure to stay on the line.
  • Deploy AI detection and transaction anomaly monitoring.
  • Adopt a 'trust, then verify—every time' culture, as recommended by J.P. Morgan Payments.

Frequently asked questions

What is a deepfake AI voice scam?

A deepfake AI voice scam uses generative AI to clone someone's voice and impersonate them in calls or voice messages, usually to authorize fraudulent payments or obtain sensitive data.

How much did Intesa Sanpaolo lose in the deepfake scam?

The bank's Fideuram arm transferred about €95 million. Roughly €53–59 million was recovered, while about €36 million remains missing after conversion to cryptocurrency.

How was the Intesa Sanpaolo fraud discovered?

Internal security systems flagged the suspicious transfers, allowing the bank to quickly alert authorities in China, Portugal and Italy and recover a large share of the funds.

Can AI voice clones be detected?

Detection is difficult. Research cited by McAfee shows 70% of people cannot confidently tell the difference, so banks are advised to rely on process controls rather than voice recognition alone.

What should banks do to prevent deepfake fraud?

Banks should require secondary verification channels, dual-approval for large transfers, staff training on red flags, and AI-based anomaly detection.

Closely related