// analysis
Fideuram: €95 million moved on a fake boss’s orders

A forged message, a cloned lawyer’s voice and €95 million in transfers: the Fideuram case raises hard questions about how payment requests are verified.
Roughly €95 million transferred in February 2026 in response to a fabricated request. On 25 September, Reuters reported a fraud at Fideuram, Intesa Sanpaolo’s private banking arm. Some funds were recovered; the ultimate cost remains to be established. Reuters
A message apparently from the boss, a familiar voice on the phone and bank details arriving by email: each communication reinforces the others. How does a business verify their origin before committing its money? This case brings that question into the banking industry itself.
An instruction apparently backed from the top
According to Corriere della Sera, Paolo Molesini, then Fideuram’s chairman, received a fake WhatsApp message attributed to Intesa Sanpaolo chief executive Carlo Messina. It described an urgent overseas financial transaction. A call using an AI imitation of a lawyer’s voice, followed by emails containing payment details, supported the story. Molesini arranged for the transfers to be made. The executive and lawyer were being impersonated; the newspaper describes the lawyer as uninvolved in the fraud. Corriere della Sera
Reuters says, citing its sources, that Fideuram’s executives were not under investigation in this case. Both banks declined to comment. The available account describes an instruction secured through deception and then passed through the organisation. The approval logs and original communications are unavailable to us. Reuters
The broader category is payment-order fraud: an impostor persuades someone to make an unexpected transfer, often by posing as an executive or supplier. France’s Cybermalveillance.gouv.fr describes several variants, some involving a compromised email account. The precise access method used in the Fideuram case is not documented in the material reviewed here. Cybermalveillance.gouv.fr
The amounts still need reconciling
The press figures do not yet form a final loss statement. Amounts below are in millions of euros, relating to the February 2026 case:
| Published information | €m | Source |
|---|---|---|
| Initial transfers, approximately | 95 | Reuters, 25/09 |
| Funds described as recovered, approximately | 53 | Reuters, 25/09 |
| Funds still missing, approximately | 36 | Reuters, 25/09 |
| Another estimate of missing funds | 39.5 | La Stampa, 26/09 |
Sources: Reuters dispatch of 25 September, accessible headline and opening of La Stampa, 26 September.
95 − 53 − 36 = €6 million: Reuters’ approximate figures leave an arithmetic gap. Its nature remains unknown. Explaining it requires a reconciliation of the transactions and their status; treating it as an additional loss would be unwarranted. La Stampa’s estimate adds a further discrepancy between the accounts.
“Recovered” also requires care. The Corriere distinguishes €40 million blocked and returned in China from €13 million seized in Portugal. Seizure immobilises funds; returning them to the victim is a further step. Those different states prevent us from calculating a definitive recovery rate here. Corriere della Sera
Fideuram’s official report for the period ended 30 June 2026 provides a separate accounting item. It records €38 million of charges unrelated to ordinary operations, within non-recurring items whose net balance is −€9 million. The commentary refers, among other things, to operational losses unrelated to client business. The passages examined do not explicitly attribute those charges to the fraud. Their numerical proximity does not make them interchangeable with September’s estimates. Fideuram, pp. 39 and 105
Measuring the ultimate cost would require matching cash outflows, completed recoveries, any outstanding claims and accounting entries. No verified case-specific figure for insurance or expenses is available here. Assets managed for clients are also an unsuitable denominator: they are not the bank’s equity available to absorb losses.
Three channels can carry one invented story
Consider a hypothetical example. A message requests a payment, a call confirms the transaction and an email supplies the bank details. If one impostor controls all three communications, their consistency can be manufactured. More channels do not guarantee an independent check.
The FBI recommends verifying payment requests with the person concerned and independently looking up contact details when a message is suspicious. Calling a number supplied by the sender can leave that sender in control of the confirmation too. The FBI also recommends multifactor authentication: using more than one element to verify access to an account. FBI
Dual approval needs similar scrutiny. Two people may approve a transaction while consulting the same falsified file. Separating their roles remains useful, but the second person needs a way to verify the underlying expense and its beneficiary. The Basel Committee’s Principle 9 brings together segregation of duties, approvals and transaction reconciliation. Basel Committee, March 2021, paragraphs 48–51
In this example, even a callback to a genuinely authorised employee can leave the problem unresolved: that employee may have been deceived about the transaction’s purpose. Verification needs to reach the invoice, contract or independently checked counterparty. Our analysis of digital identity requests explores a related question: how can the requesting party be identified and a usable record of its request retained?
Secure access can still lead to a deceptive payment
A legitimate employee can log in with their own authentication tools and enter exactly the account details they received. If the file is false, the system faithfully executes an order with no valid business purpose. This hypothetical case explains why account protection and spending controls need to work together. It does not describe Fideuram’s internal procedures.
The European Banking Authority (EBA) and the European Central Bank (ECB) provide context: in 2024, manipulation of the payer accounted for 74% of the value of fraudulent credit transfers in their EU/EEA dataset. The denominator is the reported value of fraudulent credit transfers. The figure measures neither all transfers nor the share involving AI. Coverage excludes Liechtenstein and, for credit transfers in the second half of 2024, Bulgaria. EBA-ECB report of 15 December 2025, pp. 9 and 19
The authorities also find that strong customer authentication remains effective, particularly for card payments. Those safeguards retain their value. They need complementary checks against requests that persuade the payer to act personally. EBA-ECB press release
The report also cautions that an authenticated transaction is not automatically a legally authorised transaction. Technical validation alone therefore cannot determine who should bear a loss. EBA-ECB, footnote 10, p. 20
A cloned voice strengthens the performance
The FBI’s 3 December 2024 alert describes generative AI being used to produce deceptive messages and audio with less effort. Voice cloning creates a synthetic imitation of someone’s voice. It can give a request a particularly persuasive sense of familiarity. FBI / IC3
The economic mechanism is a potential reduction in preparation costs. For Fideuram, however, the model used, the available voice recordings and the extent of live interaction are undocumented here. Journalists report an AI contribution; its specific effectiveness has not been measured.
The organisational question remains: what made the transaction appear legitimate? A voice can reinforce trust, but money still leaves through a decision and a payment process. Understanding that transition helps identify corrective measures beyond simply training staff to recognise artificial voices.
After the transfer, the state of the funds matters
Detecting a fraud, immobilising the money and returning it are separate outcomes. Cybermalveillance.gouv.fr recommends immediately alerting the bank, requesting recovery, suspending pending transfers and preserving the material needed for a complaint. Official guidance
Swift describes its Stop and Recall service as allowing a payment still in transit to be halted and a request routed to the institution handling it. The provider’s documentation illustrates why the timing of an alert matters. Its use at Fideuram has not been established. Once money has been credited and moved again, a recall request provides no universal guarantee of reversal. Swift
Reuters reports that some funds passed through overseas accounts and were converted into cryptoassets. Without authenticated transaction records, we cannot identify the platform, blockchain or route taken. Locating the assets, freezing them and returning them remain separate questions. Reuters
The procedure must hold when the boss calls
An urgent request from the top can make ordinary checks socially difficult: pausing the transaction means questioning the person giving the orders. Control design needs to anticipate that situation.
The Basel Committee calls for monitoring exceptions, including management interventions that override normal rules. Cybermalveillance.gouv.fr recommends an internal verification procedure for unexpected transfers that cannot be waived. Basel Committee, Principle 9, Cybermalveillance.gouv.fr
For Fideuram, the applicable process, the checks actually performed and the timing of alerts remain to be documented. A bypassed rule, an inadequate rule and a signal acted on too late require different remedies. The public sources reviewed here do not establish which hypothesis applies.
A useful account would distinguish money transferred, funds immobilised, completed recoveries and the ultimate cost, then explain which controls were corrected. A payment must remain verifiable when the request seems to come from someone the recipient recognises and is expected to obey.
Sources and limitations
Analysis as of 26 September 2026. Case-specific facts rely on reporting, principally Reuters and the Corriere, rather than a complete judicial file. Only La Stampa’s accessible headline and opening were reviewed. The half-year report was published by the bank concerned. No interviews, systems audit, examination of recordings or transaction tracing were performed. The examples and mechanism diagram are illustrative.
- Reuters, Emilio Parodi, 25 September 2026, reproduced by WHBL: information attributed to two anonymous sources.
- Corriere della Sera, Luigi Ferrarella, 25 September 2026: impersonation, returned funds and seizures.
- La Stampa, Andrea Siravo, 26 September 2026: a different estimate of missing funds; full text not reviewed.
- Fideuram, half-year report to 30 June 2026, pp. 39 and 105: the bank’s accounting presentation.
- EBA-ECB payment fraud report, 15 December 2025 and accompanying release: 2024 data, coverage and strong authentication.
- FBI, Business Email Compromise and IC3 alert, 3 December 2024: prevention and fraudulent uses of AI.
- Cybermalveillance.gouv.fr, guidance updated 15 September 2026: payment-order fraud, prevention and response.
- Swift, Stop and Recall: the provider’s description of its service.
- Basel Committee, revised Principles for the Sound Management of Operational Risk, March 2021: final version, Principle 9, paragraphs 48–51.
This analysis is not investment advice.
// cite this analysis
l0g, “Fideuram: €95 million moved on a fake boss’s orders”, l0g.fr, published September 26, 2026, updated September 26, 2026, https://l0g.fr/en/analysis/fideuram-fake-boss-cloned-voice-95-million/
$ cd ../analysis