Here is a number that should make every CFO, board director, and business owner stop what they are doing: $108 million. That is how much fraudsters stole from Italy’s largest bank using nothing more than an AI voice clone and a WhatsApp message.
I have been writing about AI-enabled threats for years, but this one hits differently. It is not a theoretical risk from a rogue model escaping a lab. It is practical, cheap, and devastating. And it worked against a chairman of one of Europe’s biggest financial institutions.
How the Heist Unfolded
In February 2026, Fideuram Chairman Paolo Molesini received a WhatsApp message that appeared to come from Intesa Sanpaolo CEO Carlo Messina. The message requested urgent help with an overseas transaction. Standard executive scam stuff so far.
Then the phone rang. A senior partner from a prominent law firm was on the line, confirming the instruction. The voice sounded exactly like him. Because it was him. Or rather, it was an AI clone of his voice, generated from publicly available audio.
Believing the request was genuine, Molesini instructed his finance department to arrange a series of transfers to foreign accounts, mainly in China and Hong Kong. Total stolen: €95 million, or roughly $108 million USD.
The bank recovered about €53 million through cooperation between authorities in China, Portugal, and Italy. But €36 million remains missing, converted into cryptocurrency and moved through a network of overseas accounts.
Molesini resigned as chairman in March, citing personal reasons. The bank gave no further explanation.
This Is Not a Novel Attack
If you think this sounds familiar, you are right. In 2025, fraudsters using the same technique mimicked the voice of an Italian minister and persuaded businessman Massimo Moratti to transfer nearly €1 million. That money was later recovered.
The difference now is scale. AI voice cloning has gone from a proof-of-concept trick used against wealthy individuals to a weapon capable of emptying a bank’s accounts. The technology is faster, more convincing, and cheaper than ever.
ElevenLabs, OpenAI, and others offer voice cloning tools that need as little as 30 seconds of audio to produce a convincing replica. You can find hours of any public figure on YouTube, earnings calls, or media interviews.
Why This Matters for Every Business
The traditional defence against this kind of fraud is the “verify by phone” policy. Call the person back on a known number. Use a pre-agreed passphrase. Confirm requests through a separate channel.
But those controls did not work here. The scammers called from what appeared to be a legitimate number and used AI to pass the voice test. The chairman followed the verification procedure and it still failed because the verification method itself was compromised.
Here is what needs to change:
- Codewords are not optional. Every organisation handling significant transfers should have a pre-agreed, randomly rotated passphrase that appears in no digital system. If the caller cannot produce it, the transaction stops.
- Out-of-band confirmation. Voice calls are now untrusted channels. Confirm high-value transactions through an independent system that the requester has no access to during a scam call.
- Transaction delays. The scammers moved €95 million in a series of transfers. Mandatory cooling-off periods for amounts above a threshold would have caught this.
- Train for AI-enabled social engineering. Your security awareness programme probably covers phishing emails. Does it cover the CFO getting a call from “you” asking to authorise a payment using your cloned voice?
The Bigger Picture
This is one incident on one day, but it is part of a pattern that is accelerating fast. AI messaging scams, voice clones, and deepfake impersonation are no longer futuristic threats. They are happening right now, against some of the best-resourced targets on the planet.
IBM’s 2026 Cost of a Data Breach Report found that one in four malicious breaches is now AI-enabled, costing an average of $6 million. The Intesa Sanpaolo case blows that average out of the water. And it was not even a breach in the traditional sense. No malware. No zero-day. No hacked server. Just a phone call and a cloned voice.
The FTC chairman said this week that AI developers should be liable for what their agents do. Maybe that will help at the regulatory level. But at the operational level, the defence is simpler: trust nothing you hear, verify everything through a process the attacker cannot predict, and assume that the voice on the other end of the line might not be who you think it is.
AI voice cloning has turned every phone call into a potential attack surface. The technology that makes your smart speaker feel human is the same technology that just stole $108 million from a bank. Update your verification procedures accordingly.
Related Reading
- Fake AI, Real Malware: Attackers Are Impersonating AI Brands – How attackers are using AI brands as social engineering lures.
- AI Agent Security: A Top 10 Guide – Practical security controls for the age of autonomous AI.
- Fighting Scammers with AI: How O2’s Daisy Is Changing the Game – How defenders are using AI to fight back.

