Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
S: Serious, 4/5IncidentReportedOECD: Incident

Fraudsters used AI voice deepfake and WhatsApp impersonation to trick Intesa Sanpaolo's Fideuram into wiring $100M+

In February 2026, fraudsters reportedly impersonated Intesa Sanpaolo CEO Carlo Messina via WhatsApp to Fideuram chairman Paolo Molesini. They then used an AI deepfake of a law firm partner's voice to confirm an urgent overseas transfer. The bank wired more than $100 million, mostly to accounts in mainland China and Hong Kong. Around $60.14 million was recovered with help from law enforcement, around $40.8 million remains missing, and Molesini stepped down in March 2026 citing personal reasons.

Happened February 2026

Amount still missing
Around $40.8 million
Amount wired
More than $100 million

Who is exposed

Banks, wealth managers and any firm where senior executives can instruct finance teams to make large transfers on the strength of messaging-app requests or phone calls.

What to do

Require out-of-band verification through independently sourced contact details for any urgent or confidential transfer request, however senior the requester. Add dual approval and payment holds for large international transfers, and train executives on voice-clone and messaging-app impersonation.

Rules it touches

Payment authorisation and anti-fraud controls, operational risk management and internal controls for financial institutions, and incident reporting to banking supervisors and law enforcement.

Harm, as stated in the sources

Who was involved

As named in the sources. Parties are alleged unless a source reports a finding or an admission.

Other facts

Application Security Isn’t Optional Anymore.