Scammers impersonated Intesa Sanpaolo’s CEO via a fake WhatsApp message and then used an AI-cloned voice posing as a law-firm partner to pressure Fideuram’s chairman into approving an overseas transfer. The bank sent €95 million to foreign accounts (including China and Hong Kong) before detecting anomalies; €53 million was recovered, with the remainder laundered and converted to cryptocurrency.
How the Attack Unfolded
The fraud began with a WhatsApp message that appeared to come from Intesa Sanpaolo CEO Carlo Messina, asking Fideuram's chairman for help with a large overseas transaction. This initial contact set the stage for a second, more convincing step: a phone call using an AI-cloned voice impersonating a senior partner at a major law firm. The combination of a familiar name in a messaging app and a voice that sounded like a trusted contact created a chain of validation that made the request feel legitimate.
Acting on these communications, the chairman approved transfers totaling €95 million to multiple foreign accounts, including ones in China and Hong Kong. The bank's team eventually detected anomalies in the transactions and alerted the recipient banks, leading to a partial recovery of €53 million with assistance from authorities and banks in Italy, Portugal, and China. The remaining funds were moved through overseas accounts and converted into cryptocurrency.
Why It Succeeded
This attack worked because it layered multiple forms of social proof. A message on a personal, consumer messaging channel felt informal enough to bypass normal scrutiny, while the follow-up voice call added a second identity, that of a law firm partner, to corroborate the request. Because the voice was AI-generated rather than a real person, traditional voice recognition offered no protection. The urgency embedded in the request for an overseas transfer also pressured the target to act quickly rather than pause for verification.
Red Flags to Watch For
- Executive or partner requests arriving through WhatsApp or similar consumer apps instead of official channels
- Pressure to move large sums overseas urgently
- A phone call used as "confirmation" that relies solely on recognizing a voice rather than an established verification process
- Requests involving foreign accounts in unfamiliar jurisdictions
Building Organizational Resistance
Organizations handling high-value transfers should treat any executive payment request sent via consumer messaging apps as high risk and require verification through documented, trusted channels such as known callback numbers and dual approval. Because voice calls can now be convincingly faked with AI, identity verification should go beyond voice recognition, incorporating challenge questions or out-of-band confirmation steps.
Anomaly detection processes for high-value or unusual international transfers can improve the odds of halting or reversing fraudulent transactions before funds disappear. Finally, having a rapid incident response plan that includes banking partners and law enforcement contacts can meaningfully increase the chance of recovering funds, as it did in this case when €53 million was recovered through coordinated action across multiple countries.
Key findings
- Attack started with a WhatsApp message that appeared to come from Intesa Sanpaolo CEO Carlo Messina asking for help with a large overseas transaction.
- Attackers followed up with a phone call using an AI voice clone to impersonate “a senior partner at a major law firm,” reinforcing the legitimacy of the request.
- Fideuram transferred a total of €95 million to multiple foreign accounts (including China and Hong Kong).
- The bank’s team detected anomalies and alerted recipient banks; €53 million was recovered with help from authorities and banks in Italy, Portugal, and China.
- Remaining funds moved through overseas accounts and were converted into cryptocurrency; prosecutors are investigating suspects, including “one person living outside the European Union.”
Who’s being targeted
- Commonly targeted roles: Executive leadership, Finance/Treasury, Payments operations, Private banking teams, Fraud/risk teams.
- Affected industries: Banking, Private banking, Financial services.
- Attack channels: whatsapp, vishing.
- Impersonated: Intesa Sanpaolo CEO (via WhatsApp) and a senior law-firm partner (via AI-cloned voice call).
Red flags to watch for
- Unusual request initiated via WhatsApp rather than official channels
- Urgency/pressure to move large sums overseas
- Voice call ‘confirmation’ relies on identity claims rather than a known callback/verification process
Frequently asked questions
How did the attackers first contact the victim?
Fideuram's chairman received a WhatsApp message that appeared to come from Intesa Sanpaolo CEO Carlo Messina, asking for help with a large overseas transaction.
How was AI voice cloning used in this attack?
After the WhatsApp message, attackers followed up with a phone call using an AI voice clone impersonating a senior partner at a major law firm, reinforcing the legitimacy of the request.
How much money was lost and recovered?
The bank transferred €95 million to foreign accounts, including in China and Hong Kong, and later recovered €53 million with help from authorities and banks in Italy, Portugal, and China.
What should organizations do to prevent similar scams?
Treat urgent executive payment requests sent through consumer messaging apps as high risk, verify identity through known callback channels, and assume voice calls can be deepfaked.
Read the video transcript
Picture this: a WhatsApp from your CEO pops up, “I need your help with a large overseas transaction, please proceed urgently.” That’s exactly how Fideuram got pulled into a €95 million scam: WhatsApp from “CEO Carlo Messina,” then a follow-up call from an AI-cloned voice posing as a senior law-firm partner to pressure them to send money overseas. Here’s the trap: the WhatsApp looks like your boss, and the voice on the call sounds exactly like a trusted partner, but both can be faked. The real red flag is the channel and urgency: a huge overseas transfer kicked off in a consumer chat app, “confirmed” only by a voice on the phone. If any executive asks for a payment over WhatsApp or a call, stop and do one thing: hang up, ignore the chat, and call them back using a number from our official directory before you move a cent.