Executive Impersonation Fraud: The €95M Fideuram Case

Categories: Deepfake,Published On: September 25th, 2026,
  • Dark Breacher.ai banner reading CASE ANALYSIS, EXECUTIVE IMPERSONATION, above three linked channels labeled WhatsApp message, cloned voice and email with details, captioned every channel supplied by the requester.
Case Analysis

Executive Impersonation Fraud at Fideuram: Three Channels, One Familiar Voice, €95 Million Moved

A WhatsApp message from a CEO who never sent it. A phone call in the cloned voice of a lawyer the target knew. An email with the bank details. Every channel looked real to the person receiving it, and every channel belonged to the requester.

By Jason Thatcher, Founder and CEO, Breacher.ai · September 25, 2026

Find out whether your payment approvals hold when the instruction arrives from the top.

Book Your Demo

Executive impersonation fraud has a new reference case. In February 2026, criminals impersonated the chief executive of Intesa Sanpaolo over WhatsApp, cloned the voice of a senior lawyer with AI, and persuaded the then chairman of Fideuram, the group's private banking subsidiary, to route roughly €95 million through the Fideuram treasury. Corriere della Sera broke the story this week.

Fideuram's own controls raised the alarm and most of the money came back. At least €36 million did not. It was converted into cryptocurrency before investigators could reach it.

Key takeaways
  • The chain used three channels: a WhatsApp message, a cloned voice call, and an email carrying the beneficiary details.
  • Every channel was supplied by the requester. Three sources agreeing with each other were one source speaking three times.
  • Recognizing the voice was never going to be the control. The target knew the lawyer, and the clone sounded like him.
  • The control that breaks this chain is verification on a channel the organization held before the request arrived, with no exception for seniority.

What Happened at Fideuram

The public reporting, from Corriere della Sera and carried by L'Unione Sarda, Open and Il Fatto Quotidiano, describes a sequence rather than a single message. That distinction is the whole story.

STAGE 01 · MESSAGING

A WhatsApp message from the parent company's CEO

The chairman of Fideuram received a WhatsApp message that appeared to come from Carlo Messina, chief executive of the parent, Intesa Sanpaolo. It described an urgent overseas financial transaction the group wanted to secure, and asked that the transfers run through Fideuram's treasury because Intesa, for practical reasons, could not make them itself.

STAGE 02 · VOICE

A call in the cloned voice of a lawyer he knew

A follow-up call came from someone presenting as Paolo Nastasi, managing partner of A&O Shearman in Italy, positioned as the intermediary on the deal. Nastasi was entirely unaware and uninvolved. The chairman knew him, and the voice sounded like him, because it had been replicated with AI voice cloning tools.

STAGE 03 · EMAIL

Beneficiary details by email

Email supplied the recipient bank coordinates, mostly accounts in China and Hong Kong, with further transfers reported to Portugal.

Fideuram's internal controls then raised the alert and the bank activated international interbank cooperation. According to the reporting, about €40 million was blocked in China, a Milan court order in May froze €13 million at a Portuguese bank, and the remainder moved into bitcoin. The chairman stepped down in March, citing personal reasons. Milan prosecutors are pursuing the funds through letters rogatory, with one foreign name, possibly itself a fictitious identity, entered in the investigation register.

A note on what we do not know. The reporting does not describe Fideuram's internal approval workflow, so nothing below is a verdict on anyone's judgment. It is an analysis of the pattern, and the pattern is one we see in our own work every month.

€95M
transferred in multiple wires, mostly to China and Hong Kong
€59M
of the €95M frozen or recovered after Fideuram raised the alarm
€36M
of the €95M still missing, converted into cryptocurrency

Corroboration Is Not Verification

Look at the chain from the chairman's side. A request arrives from a senior executive he knows. A second person he knows, on a second channel, confirms it in a voice he recognizes. A third channel delivers the paperwork. By any intuitive standard, the request has been checked three times.

It has not been checked once. Every one of those channels was supplied by the requester. The WhatsApp account, the phone line the call came from, and the email thread were all opened by the people running the scheme. Three sources agreeing with each other is only evidence when the sources are independent. Here they were one source speaking three times.

StageChannelSupplied byIndependent check that breaks it
Instruction from the CEOWhatsAppRequesterCall the CEO's office on the number already held in the corporate directory
Confirmation from the lawyerVoice call, clonedRequesterCall the law firm's switchboard from its published number and ask for the partner
Beneficiary detailsEmailRequesterHold any new beneficiary in a new jurisdiction until it is validated through a channel the bank already held
Payment orderInternal instructionGenuineA second approver whose sign-off cannot be waived by the seniority of the first

Only the last row was authentic, and it is the row that seniority can most easily collapse. That is the finding most organizations have never tested.

Three channels agreeing with each other is not three checks. It is one requester speaking three times.

This is what separates a modern WhatsApp CEO fraud from the business email compromise most controls were written for. The classic version relies on one convincing email. The orchestrated version assumes the target will seek confirmation, and supplies it in advance on a channel the target trusts more than email: a voice.

Why Recognizing the Voice Was Never the Control

The most important detail in the reporting is that the chairman knew the lawyer. His ear had a genuine reference, and the cloned voice matched it. Recognition did exactly what recognition does, and it was defeated by a better artifact.

That is the core of our position on AI voice cloning fraud. Human recognition of a voice is a perceptual control, and its effectiveness is an inverse function of the adversary's generation quality. Generation quality improves every quarter. Human hearing does not. A control whose strength is set by the adversary's tooling is a control with a depreciation curve attached, and we laid out the full argument in Deepfake Detection Training Is a Decaying Control.

A procedural control does not read the artifact at all. A callback to a number held in the directory returns the same answer whether the voice on the inbound call is crude or perfect. The bill got better. The check did not have to.

Two bounds keep this honest. This is not a case against technical detection. Machine controls on inbound channels, identity verification, and transaction monitoring are real layers, and Fideuram's own monitoring is what raised the alarm here. The case is against locating the control in one person's perception on one phone call. And detection-based awareness training still earns its place wherever the tell is an inspectable artifact, such as a sender domain or a header. A cloned voice leaves nothing to inspect.

The Hardest Link: A Genuine Instruction From the Top

The executive impersonation fraud playbook is built to end at a real person with real authority, because a real instruction from a real senior officer moves through an organization with almost no friction. The impersonation only has to convince one person. That person's authority does the rest.

This is where the Control Invariance Thesis gets specific. Better synthetic media does not defeat a verification procedure directly. It raises the pressure applied against it. A more convincing executive, backed by a more convincing lawyer, makes granting the exception feel reasonable. What degrades with generation quality is not the procedure. It is the exception rate.

So the procedure question is not whether a payment control existed. At a regulated bank, some form of one is standard. The question is whether any documented step could be waived by the seniority of the person invoking it. If it can, the procedure covers every employee except the ones criminals are actually targeting.

What Went Right: Speed Recovered Most of the Money

It would be easy to read this case as a pure loss. It is not. Roughly €59 million of the €95 million was frozen or recovered, about 62 percent of the total, because Fideuram's systems flagged the transfers and the bank moved fast through international interbank channels. That response deserves credit.

Recovery is a control too, and it is one most organizations never rehearse. The difference between a recalled wire and a lost one is measured in hours. A rehearsed recall playbook, with the bank contacts, the escalation path, and the legal steps written down in advance, is what turned a €95 million event into a €36 million one.

Five Controls That Break an Executive Impersonation Chain

None of these require new technology, and all of them are testable.

  1. Make an executive instruction to move funds outside the normal path its own request class. A request that asks you to act because the usual owner cannot is a trigger, not a reason.
  2. Verify on a channel you held before the request arrived. The directory number, the published switchboard, the known account. If the requester supplied the channel, the check confirms only that the requester answered their own phone.
  3. Remove seniority exceptions in writing. Senior officers should pre-commit, publicly, that their own instructions go through the same verification. Nobody, including the chairman, can waive it on the day.
  4. Hold new beneficiaries in new jurisdictions. A first payment to an account the organization has never paid should wait for independent validation, however urgent the deal.
  5. Treat confidentiality as a trigger, not an exemption. A pretext that asks you to keep the usual people out of the loop is asking you to remove the controls those people represent.

Then rehearse the recall. Know who you call at your bank in the first hour, and practice it before you need it.

How to Test the Chain Before Criminals Do

Most simulation programs send one email and measure a click. The Fideuram chain would sail through that test, because no single message in it was the failure. The failure lived in the sequence, which means the only honest test is a sequence.

That is what the Breacher.ai orchestrated social engineering simulation engine, OSES™, was built to do. It chains messaging, synthetic voice, and email into one authorized campaign, and each stage adapts to what the target did at the stage before. Live conversational AI handles the call, and agentic inbound callback handling answers when a target dials back. That last capability matters more than it sounds: it lets us tell a verification step that ran on the organization's own channel from one that ran on the channel the pretext supplied. Those look identical in a click report and they are opposite outcomes.

Findings are named against procedures, not people. You learn whether your callback rule held, whether the second approver held, and whether seniority collapsed either of them. For the executive impersonation path specifically, our CEO fraud simulation tests the full approval chain, and no money moves. The voice stage runs through our vishing simulation capability.

And the training side keeps pace with the headlines. With OSES™ Behave, part of the Breacher.ai simulation platform, a security team can drop an article like this one into the platform and generate both the simulation and the matching awareness module in minutes, aligned to its own payment procedures rather than a generic library. The module a person receives is the procedure they did not follow.

The trend in our own data is the reason to move now. In live agentic voice simulations, roughly one in ten targeted users now completes a consequential action, up from the low single digits when we started measuring, with our methodology held constant. The models improved. The procedure is the part you control. The companion argument for binding verification to the request class is in Process Invocation vs. Detection.

Questions to Ask Your Finance Team This Week

If the CEO messaged you on WhatsApp asking for an urgent transfer, which written step would you follow, and does it name a channel?
Could a request that arrives through an executive's personal messaging account ever reach the treasury without a callback?
Is there any payment step that a sufficiently senior officer can waive on the day?
When someone confirms a request, do you know whether the channel was yours or theirs?
What happens to a first payment to a new beneficiary in a new jurisdiction?
Who calls the bank in the first hour after a suspect wire, and have they ever practiced it?
Measure your risk. Train for what you find. Prove it changed.

Frequently Asked Questions

What happened in the Fideuram executive impersonation fraud?

In February 2026, criminals impersonated Intesa Sanpaolo chief executive Carlo Messina over WhatsApp and asked the then chairman of Fideuram to route an urgent overseas transaction through the Fideuram treasury. A follow-up call used an AI-cloned voice of a lawyer the chairman knew, and email supplied the bank details. About 95 million euros was transferred, mostly to China and Hong Kong. Fideuram's controls raised the alarm and roughly 59 million euros was frozen or recovered, while at least 36 million euros was converted into cryptocurrency.

How was AI voice cloning used in the Fideuram case?

The voice clone was used for corroboration, not for the initial request. After the WhatsApp message arrived, a caller presenting as a managing partner of an international law firm, someone the chairman knew personally, confirmed the transaction in a replicated voice. The lawyer was entirely unaware. The clone turned a single suspicious message into what felt like independent confirmation from a trusted second party.

Why did recognizing the voice not protect the target?

Recognizing a voice is a perceptual judgment, and synthetic voice quality is now good enough that the human ear cannot be relied on to tell the difference, even for voices the listener knows well. A perceptual control weakens every time generation models improve. A procedural control, such as calling back on a number the organization already held, returns the same result against a crude clone and a perfect one, because it never evaluates the voice at all.

What is the difference between corroboration and verification?

Corroboration is agreement between sources. Verification is confirmation through a channel the requester does not control. In the Fideuram chain, the WhatsApp message, the voice call and the email all agreed, but all three were supplied by the requester, so they added up to one source speaking three times. Verification means dialing the directory number, the published switchboard or the known account, never the number or thread the request provided.

Could deepfake detection technology have stopped it?

Technical controls are a valuable layer, and Fideuram's own monitoring is what raised the alarm and enabled most of the recovery. But the decisive moment was an ordinary phone call from a voice the target knew, a point where no human listener could be expected to catch the fake. The durable control is procedural: verification through a channel the organization already held, with no exception for seniority, backed by technical monitoring and a rehearsed recall process.

How do you test whether executive impersonation controls hold?

Run the sequence, not a single message. An orchestrated simulation chains messaging, voice and email into one authorized campaign, adapts each stage to what the target did at the last one, and records whether verification ran, whether it ran on the organization's own channel or the one the pretext supplied, and whether seniority waived it. Breacher.ai runs these engagements with findings named against procedures, and no money moves.

Sources. Case details are drawn from public reporting first published by Corriere della Sera on September 25, 2026, as carried by L'Unione Sarda, Open and Il Fatto Quotidiano. Figures are as reported and may change as the investigation proceeds.

JT

Jason ThatcherFounder and CEO of Breacher.ai. Fifteen years in security operations and offensive testing, previously at ZeroFox, Deepwatch, and GuidePoint Security. He builds orchestrated social engineering simulations that test whether enterprise verification procedures hold under pressure.

Would Your Approval Chain Hold Against a Voice You Know?

We run the full sequence, message to voice to email, and report whether your verification step ran, which channel it ran on, and whether seniority waived it. No money moves.

Book Your Demo

Latest Posts

  • Executive Impersonation Fraud: The €95M Fideuram Case

  • Breacher.ai Launches the Secure Behavior Management Platform

  • Process Invocation vs. Detection | Breacher.ai

Table Of Contents

About the Author: Jason Thatcher

Jason Thatcher is the Founder of Breacher.ai and comes from a long career of working in the Cybersecurity Industry. His past accomplishments include winning Splunk Solution of the Year in 2022 for Security Operations.

Share this post