In February 2026, fraudsters came close to taking 95 million euros from Fideuram, the private banking arm of Intesa Sanpaolo that manages 450 billion euros in client assets, using nothing more exotic than a fake WhatsApp message and a cloned voice. The scheme started with a message that appeared to come from Carlo Messina, chief executive of Intesa Sanpaolo, asking for urgent fund transfers out of Fideuram's treasury to cover an overseas financial operation.

What made the message convincing enough to act on was the phone call that followed it. The fraudsters used AI generated voice technology to impersonate Paolo Nastasi, a lawyer known to Paolo Molesini, Fideuram's president at the time, reproducing his voice closely enough to lend the WhatsApp request the credibility a text message alone could not supply. Between a message that looked like it came from the top of the bank's parent company and a voice that sounded like someone Molesini already trusted, the fraud cleared the two checks that normally stop a transfer request in its tracks, apparent authority and a familiar voice confirming it.

Fideuram and Milan's prosecutors moved to claw the money back internationally once the fraud was discovered, and recovered most of it. The final loss came to 36 million euros, meaning roughly 59 million was traced and returned, a recovery rate that still leaves a private bank managing nearly half a trillion euros nursing a nine figure hole from a single phone call and a single message.

The case lands squarely inside a trend security researchers have been describing in increasingly specific terms. Anthropic's own threat report from September 2026 put it plainly, artificial intelligence has narrowed the resource gap between state level operations and individual criminals, meaning a convincing voice clone and a well timed message no longer require the kind of organized, well funded operation that CEO fraud used to demand. What used to take a criminal network with inside knowledge and real acting talent can now be assembled by someone with an AI voice tool and a plausible enough story.

For Fideuram, and for every institution built around trusting a familiar voice on the other end of a phone, the lesson is not that the fraud was unusually sophisticated. It is that it did not need to be. A cloned voice and a spoofed message got further, faster, against better defenses than almost any pre AI version of the same scam could have managed, and 36 million euros is what it cost to learn exactly how far.