Bitcoin Mix
© 2026 mixerbtcpro.com | All rights reserved.
  • Protecting your privacy since 2017.
  • TOR v3: http://blenderxzgdsdrdsz5rkuh6e6fpe6zckdpos2tuscp4epmyngmbcqmqd.onion
  • Service address: 33M4cJM3egGFhLk65jbH5JTar8L5tYWWxD
  • PGP keys: B894D26778F08535
Financial AI

Fideuram and the voice deepfake: how fraudsters triggered €95M in transfers

In September, media reported a fraud that began in February 2026: former Fideuram chairman Paolo Molesini authorised a series of transfers totalling about €95 million after a WhatsApp message and a call using a cloned voice. A substantial share was frozen or recovered, though public accounts differ on the precise remaining amount. The case is a useful example of AI-enabled impersonation risk in financial operations.

Fideuram and the voice deepfake: how fraudsters triggered €95M in transfers

What is known about the scheme

Reuters reporting and Italian media accounts say the fraudsters made a WhatsApp message appear to be a request from Intesa Sanpaolo chief executive Carlo Messina. A caller then used a voice resembling that of a law-firm partner to reinforce the urgency of the request.

A series of international transfers followed, adding up to about €95 million. Public reports say the incident was detected soon afterward and that a portion of the money was frozen or recovered with assistance from authorities in multiple countries.

Why a familiar voice is no longer proof of identity

Voice deepfakes can be particularly persuasive when paired with prepared context: a familiar name, a plausible communication channel, urgency, and supporting documents. The combination targets normal human trust as much as it targets technology.

This should not be confused with a compromise of a bank's core system. Published accounts describe social engineering and impersonation. A familiar voice on a call is not evidence that an instruction genuinely came from the named person.

Checks that matter for high-value transfers

Critical payments should be confirmed through a pre-agreed independent route: a known directory number, a separate approval system, or an in-person check under an established procedure. Calling back a number included in the incoming message is insufficient because it may belong to the attacker.

Separating authority also helps. The person who receives an unusual instruction should not be able to complete the transfer alone. A pause, a second approver, and a review of a new beneficiary can be more effective than trying to identify a synthetic voice by ear.

Practical takeaway for users

Treat a message demanding an urgent transfer, crypto purchase, or disclosure of credentials as unverified even when the voice or name seems familiar. Do not share a seed phrase, confirmation code, or wallet access under pressure from a caller.

The Fideuram case shows that AI can strengthen a long-standing impersonation scheme rather than replace basic safety rules. Effective protection rests on independent confirmation, limits, and the ability to halt a transaction when the circumstances do not add up.

Back to blog Open Bitcoin Mix