What happened
In February 2026, the chairman of Fideuram, the private banking arm of Intesa Sanpaolo, received a WhatsApp message from the CEO of the group. The profile was fake. The request was specific: a series of urgent transfers through Fideuram’s treasury, for a deal abroad.
Then came a phone call. On the line was a managing partner of a large international law firm, a lawyer the chairman knew. It wasn’t him: his voice had been cloned with AI, and the real lawyer had nothing to do with any of it. After the call, an email arrived with the bank details.
About €95 million left the bank, mostly towards China and Hong Kong. An internal alarm went off quickly, and international interbank cooperation clawed back a large part of it: over €40 million blocked by a Chinese bank, €13 million seized in Portugal at the request of Milan prosecutors. At least €36 million is still missing, converted into crypto before anyone could freeze it.
The chairman is not under investigation. He stepped down in March, officially for personal reasons. The story only became public on 25 September, when Corriere della Sera reported it from the prosecutors’ files.
One detail matters more than the numbers: the bank’s IT systems were not breached. There was no malware, no stolen password, no exploit. A chat message, a phone call and an email moved €95 million out of a bank’s treasury.
One step past the PEC case
Earlier this week I wrote about Revolut and a stolen government PEC mailbox. That attack, I said, needed no zero-day and no deepfake. This one used a deepfake, and it’s the same attack one level up.
In the PEC case the channel was real. The mailbox belonged to a government agency, the seals were valid, and only the request inside was false. The lesson was that a trusted channel is not a trusted request.
Here nothing is real. The WhatsApp profile is fake, the voice is synthetic, the email is just an email. What the attackers forged is identity, and they forged it twice, borrowing two people the chairman had every reason to trust: the head of the group that owns his bank, and a lawyer he knew personally.
My reading of the sequence, which the reports don’t spell out, is that each fake covers the other’s weak spot. Anyone can put a name and a photo on a WhatsApp profile, so a message from the CEO alone can be doubted. A call from a familiar lawyer, confirming the deal, answers that doubt. The call alone would be odd, a lawyer asking a bank chairman to move money, until you’ve read the CEO’s message. And by the time the email with the bank details arrives, after two confirmations, it looks like paperwork.
No single message had to be convincing. The sequence did. That’s what a well-made CEO fraud looks like in 2026, and it’s why checking the channel isn’t enough anymore: here even checking the voice with your own ears failed.
The lever is the org chart
It’s tempting to say the chairman should have known better. I don’t think that’s useful, and it’s not what I’d take away from this. Anyone who has worked in a company knows how a request from the top lands: you don’t ask the CEO of the group to prove he’s the CEO of the group. The attackers didn’t pick that name by chance. The weak point they aimed at was the org chart, not a person.
A bank treasury has controls: authorisation limits, dual approval, checks on new beneficiaries. We don’t know which ones Fideuram had, or how they were applied that day. One report says the chairman instructed the finance director to execute the transfers. If that’s how it went, the four-eyes principle may well have been respected on paper, with two people involved. But when the second pair of eyes reports to the first, you have two eyes, not four.
That’s the pattern I’d look for in any company, not just a bank: the higher the request comes from, the fewer checks it goes through. Controls get designed to stop a clerk from paying a fake invoice, and quietly stop applying when the instruction comes from the chairman or the CEO. Add urgency and a deal abroad, the kind of thing nobody discusses in the corridor, and the request never meets anyone who is in a position to say no.
The part of the process that did work came afterwards. The alarm went off quickly, and interbank cooperation brought back a large share of the money. That’s a good downstream control. It’s also a control that only starts once the money has already left.
Recognising a voice is no longer verification
CEO fraud is not new, and it’s not rare. In the companies I’ve worked with, past and present, accounts payable gets emails in the CEO’s name several times a month, asking for a payment to unblock some process. Most of them are crude. The well-made ones have always been stopped the same way: a second, independent check.
The check that works is simple. You contact the requester directly, on a channel you already know and trust: the number in the company directory, their assistant, their office down the hall. Never the number, address or contact that came with the request.
It works because of an asymmetry. The attacker controls everything that reaches you: the message, the profile picture, the number on your screen, and now the voice. They don’t control the call you make yourself, to a contact you had before the request existed. Voice cloning makes “I recognised him” worthless as proof. It does nothing against “I called him back on the number I already had”.
The same logic applies to the lawyer’s call in the Fideuram case. It worked as a confirmation, but nobody asked for it: it arrived on its own, on a channel chosen by the attackers. A confirmation that shows up by itself is part of the attack, not a check on it. My guess, and it is only a guess, is that one call to the CEO’s office, on an internal number, would have ended the whole thing at the first message.
The attackers won’t run out of material. Intesa’s head of security says the group has taken down about 5,000 AI-generated fake videos of its CEO since January. The CEO of a large company is a public figure: his face and voice are everywhere. So the rule can’t depend on spotting the fake. It has to hold even when the fake is perfect.
Takeaways
- A confirmation you didn’t ask for is part of the attack.
- Recognising a voice is no longer verification.
- Call back on a contact you already had, never on one that came with the request.
- Four eyes don’t count if one pair reports to the other.
- The higher the request comes from, the stricter the check, not the looser.