Language

30 Sep 2026 in News

When AI Fraud Fakes the Whole Chain of Trust: Inside a €95M Bank Scam

Reuters has revealed details of a sophisticated fraud scheme that cost Fideuram, the private-banking arm of Intesa Sanpaolo, around €95 million. The attackers did not simply impersonate one executive. They recreated what appeared to be an entire chain of trusted corporate communication around an urgent, confidential transaction.

The scheme began with a WhatsApp message apparently from Intesa Sanpaolo CEO Carlo Messina, asking then-Fideuram Chairman Paolo Molesini to help with an overseas operation. Molesini was then contacted by someone posing as a senior lawyer he knew, with the attackers reportedly using AI to reproduce the lawyer’s voice. At the same time, Fideuram’s head of treasury and payments received a message from someone claiming to be Fideuram’s CEO, warning that urgent transfers were coming.

Together, these interactions created a coherent approval narrative: a senior executive initiated the request, a trusted external figure appeared to confirm it, and another internal executive appeared to prepare the payments team for the transaction.

The result was around €95 million transferred mainly to accounts in China and Hong Kong. More than half was later recovered, but around €36 million remains missing.

The attack went beyond impersonation

Deepfake fraud is often discussed as a problem of recognizing a fake face or voice. This case shows why that view is too narrow.

The attackers created a sequence in which one interaction appeared to support another. The transaction therefore did not depend on one synthetic signal being accepted in isolation. The surrounding story made each part more believable.

That creates a bigger problem for high-risk transactions:

“This is not just about deepfakes. Attackers can now reconstruct an entire approval chain, making every individual message appear consistent with the next. High-risk transactions therefore need identity and authority to be verified at the point of action, through an independent channel, not inferred from a familiar face, voice, or messaging account.”

– Henry Patishman, Executive Vice President of Identity Verification Solutions

From static checks to contextual trust

The attack also shows the limits of relying on confirmation that remains inside the context created by the attacker.

If a suspicious request is validated through another message, call, or person who is already part of the fabricated scenario, that additional confirmation may reinforce the fraud instead of exposing it.

For high-risk actions, verification needs an independent anchor and a broader context. The organization should be able to establish separately:

  • Who is requesting or approving the action?

  • What authority does that person actually have?

  • Does that authority cover this specific action?

  • Does the transaction itself make sense in its current context?

This last question matters especially. Banks already verify payment details and apply transaction controls, but AI-assisted impersonation makes contextual decisioning more important. A payment should not be considered trustworthy simply because the identities, accounts, or instructions involved appear individually valid. The destination, amount, timing, previous activity, authorization path, and other available evidence need to make sense together.

In other words, trust depends on how the identity, authority, transaction, recipient, and timing fit together – in context.

Subscribe

We’ll deliver hand-picked content from Regula’s experts into your inbox

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules