
A sophisticated scam using a voice clone and WhatsApp has targeted Intesa's wealth management subsidiary Sanpaolo.
AI-generated summary
Presidential fraud is a social engineering technique exploiting urgency and authority. The use of voice clones by AI reinforces the credibility of these attacks.
Fake WhatsApp, real hemorrhage. In February, Fideuram's treasury shipped nearly 95 million euros to China and Hong Kong. The order appeared to come from Carlo Messina, CEO of Intesa Sanpaolo, the same bank that had just declared nearly $100 million in Bitcoin ETFs in cash.
It actually came from a team of fraudsters equipped with a voice clone. The bank has since recovered 53 million thanks to interbank cooperation and the Milan public prosecutor's office. The missing 39.5 million were converted into cryptocurrencies, and investigators are multiplying requests for assistance to follow the trail before the scammers cash in.
Fideuram: a fake WhatsApp, then a voice cloned by AI
Last week, in its article the media Le Corriere della Sera reconstructed the chronology. On February 23, Fideuram president Paolo Molesini received a WhatsApp message bearing the identity of Carlo Messina. The text explains that practical constraints prevent Intesa Sanpaolo from carrying out a series of transfers itself and that it is therefore necessary to go through the subsidiary's treasury so as not to let a financial transaction slip away abroad. The total requested reaches almost 95 million euros, a drop in the bucket compared to the 450 billion managed by this Italian leader in private banking.
Fraud against the president always relies on the same principle, urgency coupled with hierarchical authority. The scammers have added a technological layer to it.
So, Paolo Molesini's phone rings shortly after, and the voice on the line is that of Paolo Nastasi, managing partner of A&O Shearman Italia and a business lawyer whom he knows personally. Except the lawyer never called. Its stamp was reproduced by artificial intelligence, and the firm, born from the merger between Allen & Overy and Shearman & Sterling, had nothing to do with the operation.
The financial director of Fideuram carries out the instructions of its president, who himself believes he is carrying out that of the group's number one. Most of the money goes to China and Hong Kong.
A few seconds of recording are now enough for speech synthesis tools to reproduce a tone, and the public interventions of a leader provide more than enough. The British engineering group Arup experienced this in Hong Kong in 2024, when one of its employees transferred $25 million following a videoconference where all the people they spoke to were deepfakes. The FBI has recorded $2.77 billion in reported losses for this type of wire transfer scam in 2024 alone.
53 million euros recovered between China and Portugal
However, internal controls reacted quickly. As soon as the bank understands the extent of the trap, it activates international interbank cooperation channels. A Chinese establishment freezes 40 million euros and returns them.
Then the investigation opened in Milan into the Fideuram complaint, filed by lawyer Guido Alleva, was connected to the Lisbon public prosecutor's office under the aegis of Eurojust. Prosecutors Alfonso Serritiello and Barbara Benzi manage to block an additional 13 million in a Portuguese bank, seized by preliminary investigation judge Sonia Mancini.
On March 12, Paolo Molesini left the presidency of Fideuram. The group's press release cited "personal reasons". The former president is neither implicated by the investigation nor targeted by litigation from his own employer, which does not prevent him from joining the list of Italian leaders trapped in the same way, after Sisal for 5.5 million euros and Maire Tecnimont for 18 million.
Crypto: conversion to bitcoin, last link and weak point
39.5 million euros remain, evaporated in a series of foreign accounts before being switched to cryptocurrencies. Milanese investigators are increasing the number of rogatories (these requests for mutual legal assistance addressed to foreign authorities) to follow the trail before the fraudsters monetize their bitcoins.
The crypto part of the case is undoubtedly the one which offers the most leverage to justice. The sums sent by transfer were diluted in Asian bank accounts where transparency has never been the primary virtue, and it took the goodwill of a Chinese establishment to repatriate 40 million. Each on-chain transfer remains recorded in a public register that can be consulted by anyone, and companies like Chainalysis, Elliptic and TRM Labs have made a business out of it.
The precedents are documented. In June 2021, the FBI recovered 63.7 bitcoins from the ransom paid by Colonial Pipeline, just weeks after the attack. In February 2022, American justice seized 94,636 bitcoins linked to the 2016 Bitfinex hack, or $3.6 billion at the time, six years after the facts. The point of friction is at the exit, on the exchange platforms where customer identification is mandatory.
AI outlook — possibilities, not facts
Continuation of requests for international legal assistance.
Very likely · Within months

The alleged perpetrator of the $3.8 million theft from NEAR Intents responded to Alex Shevchenko's ultimatum by sending 1 BNB and a message via blockchain, requesting a chat on the Signal app for trading.

Two Dallas men, Damian Vielma and Jeremiah Clybourn, were arrested for an attempted armed burglary in San Jose. Posing as delivery men, they targeted cryptocurrency holders in the San Francisco Bay Area.

Two homejacking attempts aimed at stealing cryptocurrencies targeted the same couple in Saint-Jean-de-Védas near Montpellier, in April and September 2026. Three suspects aged 19, 30 and 38 were arrested during the second attempt after triggering the perimeter alarm. The first incident in April involved a 25-year-old fake armed delivery man, arrested in Marseille. The PNACO reports an increase in crypto-kidnappings in France with 135 cases since 2023.

A 24-year-old Amsterdam man, suspected of being an alleged leader of the cybercriminal group ShinyHunters, was arrested on September 15, 2026 in Amsterdam. Investigators found elements in his computer suggesting an attempt to incite two murders abroad. The group, active since 2019, is known for stealing data and demanding bitcoin payments, having targeted companies like Ticketmaster and AT&T.

Between September 15 and 20, 11.75 million XRP was stolen from 6,678 accounts linked to the D'CENT mobile application. Attackers used the AccountDelete function of the XRP Ledger to siphon funds after a private key compromise.

In Taverny, three hooded men kidnapped a family to extort cryptocurrencies based on tax data stolen from Waltio in January 2026. The targeted assets dated from 2024 and had declined significantly, limiting the loot to a few hundred euros. Six suspects were indicted, including three in pre-trial detention, and the alleged mastermind is believed to be a man imprisoned in Auxerre.