Executive Impersonation Fraud: The €95M Fideuram Case
Executive Impersonation Fraud at Fideuram: Three Channels, One Familiar Voice, €95 Million Moved
A WhatsApp message from a CEO who never sent it. A phone call in the cloned voice of a lawyer the target knew. An email with the bank details. Every channel looked real to the person receiving it, and every channel belonged to the requester.
Executive impersonation fraud has a new reference case. In February 2026, criminals impersonated the chief executive of Intesa Sanpaolo over WhatsApp, cloned the voice of a senior lawyer with AI, and persuaded the then chairman of Fideuram, the group's private banking subsidiary, to route roughly €95 million through the Fideuram treasury. Corriere della Sera broke the story this week.
Fideuram's own controls raised the alarm and most of the money came back. At least €36 million did not. It was converted into cryptocurrency before investigators could reach it.
- The chain used three channels: a WhatsApp message, a cloned voice call, and an email carrying the beneficiary details.
- Every channel was supplied by the requester. Three sources agreeing with each other were one source speaking three times.
- Recognizing the voice was never going to be the control. The target knew the lawyer, and the clone sounded like him.
- The control that breaks this chain is verification on a channel the organization held before the request arrived, with no exception for seniority.
What Happened at Fideuram
The public reporting, from Corriere della Sera and carried by L'Unione Sarda, Open and Il Fatto Quotidiano, describes a sequence rather than a single message. That distinction is the whole story.
A WhatsApp message from the parent company's CEO
The chairman of Fideuram received a WhatsApp message that appeared to come from Carlo Messina, chief executive of the parent, Intesa Sanpaolo. It described an urgent overseas financial transaction the group wanted to secure, and asked that the transfers run through Fideuram's treasury because Intesa, for practical reasons, could not make them itself.
A call in the cloned voice of a lawyer he knew
A follow-up call came from someone presenting as Paolo Nastasi, managing partner of A&O Shearman in Italy, positioned as the intermediary on the deal. Nastasi was entirely unaware and uninvolved. The chairman knew him, and the voice sounded like him, because it had been replicated with AI voice cloning tools.
Beneficiary details by email
Email supplied the recipient bank coordinates, mostly accounts in China and Hong Kong, with further transfers reported to Portugal.
A genuine internal instruction
The payments were ordered through Fideuram's finance function. This leg was not impersonated. It was a real instruction from a real chairman, which is exactly why it carried the weight it did.
Fideuram's internal controls then raised the alert and the bank activated international interbank cooperation. According to the reporting, about €40 million was blocked in China, a Milan court order in May froze €13 million at a Portuguese bank, and the remainder moved into bitcoin. The chairman stepped down in March, citing personal reasons. Milan prosecutors are pursuing the funds through letters rogatory, with one foreign name, possibly itself a fictitious identity, entered in the investigation register.
A note on what we do not know. The reporting does not describe Fideuram's internal approval workflow, so nothing below is a verdict on anyone's judgment. It is an analysis of the pattern, and the pattern is one we see in our own work every month.
Corroboration Is Not Verification
Look at the chain from the chairman's side. A request arrives from a senior executive he knows. A second person he knows, on a second channel, confirms it in a voice he recognizes. A third channel delivers the paperwork. By any intuitive standard, the request has been checked three times.
It has not been checked once. Every one of those channels was supplied by the requester. The WhatsApp account, the phone line the call came from, and the email thread were all opened by the people running the scheme. Three sources agreeing with each other is only evidence when the sources are independent. Here they were one source speaking three times.
| Stage | Channel | Supplied by | Independent check that breaks it |
|---|---|---|---|
| Instruction from the CEO | Requester | Call the CEO's office on the number already held in the corporate directory | |
| Confirmation from the lawyer | Voice call, cloned | Requester | Call the law firm's switchboard from its published number and ask for the partner |
| Beneficiary details | Requester | Hold any new beneficiary in a new jurisdiction until it is validated through a channel the bank already held | |
| Payment order | Internal instruction | Genuine | A second approver whose sign-off cannot be waived by the seniority of the first |
Only the last row was authentic, and it is the row that seniority can most easily collapse. That is the finding most organizations have never tested.
This is what separates a modern WhatsApp CEO fraud from the business email compromise most controls were written for. The classic version relies on one convincing email. The orchestrated version assumes the target will seek confirmation, and supplies it in advance on a channel the target trusts more than email: a voice.
Why Recognizing the Voice Was Never the Control
The most important detail in the reporting is that the chairman knew the lawyer. His ear had a genuine reference, and the cloned voice matched it. Recognition did exactly what recognition does, and it was defeated by a better artifact.
That is the core of our position on AI voice cloning fraud. Human recognition of a voice is a perceptual control, and its effectiveness is an inverse function of the adversary's generation quality. Generation quality improves every quarter. Human hearing does not. A control whose strength is set by the adversary's tooling is a control with a depreciation curve attached, and we laid out the full argument in Deepfake Detection Training Is a Decaying Control.
A procedural control does not read the artifact at all. A callback to a number held in the directory returns the same answer whether the voice on the inbound call is crude or perfect. The bill got better. The check did not have to.
Two bounds keep this honest. This is not a case against technical detection. Machine controls on inbound channels, identity verification, and transaction monitoring are real layers, and Fideuram's own monitoring is what raised the alarm here. The case is against locating the control in one person's perception on one phone call. And detection-based awareness training still earns its place wherever the tell is an inspectable artifact, such as a sender domain or a header. A cloned voice leaves nothing to inspect.
The Hardest Link: A Genuine Instruction From the Top
The executive impersonation fraud playbook is built to end at a real person with real authority, because a real instruction from a real senior officer moves through an organization with almost no friction. The impersonation only has to convince one person. That person's authority does the rest.
This is where the Control Invariance Thesis gets specific. Better synthetic media does not defeat a verification procedure directly. It raises the pressure applied against it. A more convincing executive, backed by a more convincing lawyer, makes granting the exception feel reasonable. What degrades with generation quality is not the procedure. It is the exception rate.
So the procedure question is not whether a payment control existed. At a regulated bank, some form of one is standard. The question is whether any documented step could be waived by the seniority of the person invoking it. If it can, the procedure covers every employee except the ones criminals are actually targeting.
What Went Right: Speed Recovered Most of the Money
It would be easy to read this case as a pure loss. It is not. Roughly €59 million of the €95 million was frozen or recovered, about 62 percent of the total, because Fideuram's systems flagged the transfers and the bank moved fast through international interbank channels. That response deserves credit.
Recovery is a control too, and it is one most organizations never rehearse. The difference between a recalled wire and a lost one is measured in hours. A rehearsed recall playbook, with the bank contacts, the escalation path, and the legal steps written down in advance, is what turned a €95 million event into a €36 million one.
Five Controls That Break an Executive Impersonation Chain
None of these require new technology, and all of them are testable.
- Make an executive instruction to move funds outside the normal path its own request class. A request that asks you to act because the usual owner cannot is a trigger, not a reason.
- Verify on a channel you held before the request arrived. The directory number, the published switchboard, the known account. If the requester supplied the channel, the check confirms only that the requester answered their own phone.
- Remove seniority exceptions in writing. Senior officers should pre-commit, publicly, that their own instructions go through the same verification. Nobody, including the chairman, can waive it on the day.
- Hold new beneficiaries in new jurisdictions. A first payment to an account the organization has never paid should wait for independent validation, however urgent the deal.
- Treat confidentiality as a trigger, not an exemption. A pretext that asks you to keep the usual people out of the loop is asking you to remove the controls those people represent.
Then rehearse the recall. Know who you call at your bank in the first hour, and practice it before you need it.
How to Test the Chain Before Criminals Do
Most simulation programs send one email and measure a click. The Fideuram chain would sail through that test, because no single message in it was the failure. The failure lived in the sequence, which means the only honest test is a sequence.
That is what the Breacher.ai orchestrated social engineering simulation engine, OSES™, was built to do. It chains messaging, synthetic voice, and email into one authorized campaign, and each stage adapts to what the target did at the stage before. Live conversational AI handles the call, and agentic inbound callback handling answers when a target dials back. That last capability matters more than it sounds: it lets us tell a verification step that ran on the organization's own channel from one that ran on the channel the pretext supplied. Those look identical in a click report and they are opposite outcomes.
Findings are named against procedures, not people. You learn whether your callback rule held, whether the second approver held, and whether seniority collapsed either of them. For the executive impersonation path specifically, our CEO fraud simulation tests the full approval chain, and no money moves. The voice stage runs through our vishing simulation capability.
And the training side keeps pace with the headlines. With OSES™ Behave, part of the Breacher.ai simulation platform, a security team can drop an article like this one into the platform and generate both the simulation and the matching awareness module in minutes, aligned to its own payment procedures rather than a generic library. The module a person receives is the procedure they did not follow.
The trend in our own data is the reason to move now. In live agentic voice simulations, roughly one in ten targeted users now completes a consequential action, up from the low single digits when we started measuring, with our methodology held constant. The models improved. The procedure is the part you control. The companion argument for binding verification to the request class is in Process Invocation vs. Detection.
Questions to Ask Your Finance Team This Week
Frequently Asked Questions
What happened in the Fideuram executive impersonation fraud?
In February 2026, criminals impersonated Intesa Sanpaolo chief executive Carlo Messina over WhatsApp and asked the then chairman of Fideuram to route an urgent overseas transaction through the Fideuram treasury. A follow-up call used an AI-cloned voice of a lawyer the chairman knew, and email supplied the bank details. About 95 million euros was transferred, mostly to China and Hong Kong. Fideuram's controls raised the alarm and roughly 59 million euros was frozen or recovered, while at least 36 million euros was converted into cryptocurrency.
How was AI voice cloning used in the Fideuram case?
The voice clone was used for corroboration, not for the initial request. After the WhatsApp message arrived, a caller presenting as a managing partner of an international law firm, someone the chairman knew personally, confirmed the transaction in a replicated voice. The lawyer was entirely unaware. The clone turned a single suspicious message into what felt like independent confirmation from a trusted second party.
Why did recognizing the voice not protect the target?
Recognizing a voice is a perceptual judgment, and synthetic voice quality is now good enough that the human ear cannot be relied on to tell the difference, even for voices the listener knows well. A perceptual control weakens every time generation models improve. A procedural control, such as calling back on a number the organization already held, returns the same result against a crude clone and a perfect one, because it never evaluates the voice at all.
What is the difference between corroboration and verification?
Corroboration is agreement between sources. Verification is confirmation through a channel the requester does not control. In the Fideuram chain, the WhatsApp message, the voice call and the email all agreed, but all three were supplied by the requester, so they added up to one source speaking three times. Verification means dialing the directory number, the published switchboard or the known account, never the number or thread the request provided.
Could deepfake detection technology have stopped it?
Technical controls are a valuable layer, and Fideuram's own monitoring is what raised the alarm and enabled most of the recovery. But the decisive moment was an ordinary phone call from a voice the target knew, a point where no human listener could be expected to catch the fake. The durable control is procedural: verification through a channel the organization already held, with no exception for seniority, backed by technical monitoring and a rehearsed recall process.
How do you test whether executive impersonation controls hold?
Run the sequence, not a single message. An orchestrated simulation chains messaging, voice and email into one authorized campaign, adapts each stage to what the target did at the last one, and records whether verification ran, whether it ran on the organization's own channel or the one the pretext supplied, and whether seniority waived it. Breacher.ai runs these engagements with findings named against procedures, and no money moves.
Sources. Case details are drawn from public reporting first published by Corriere della Sera on September 25, 2026, as carried by L'Unione Sarda, Open and Il Fatto Quotidiano. Figures are as reported and may change as the investigation proceeds.
Would Your Approval Chain Hold Against a Voice You Know?
We run the full sequence, message to voice to email, and report whether your verification step ran, which channel it ran on, and whether seniority waived it. No money moves.
Book Your Demo
