Fraudsters who deployed artificial intelligence to impersonate directors and other senior officials persuaded Fideuram, the private banking division of Intesa Sanpaolo, to transfer €95 million into accounts abroad, according to two sources close to the situation. The incident marks one of the largest known AI-enabled thefts from a European bank and raises fresh questions about the vulnerability of financial institutions to increasingly sophisticated synthetic media attacks.
The scammers are understood to have used AI-generated voice or video technology to mimic the identities of high-ranking executives, convincing staff at the private banking unit that the transfers were legitimate. The money was moved to overseas accounts before the fraud was detected. Intesa Sanpaolo, Italy's largest banking group, has not publicly commented on the reported loss, and it remains unclear whether any of the funds have been recovered or whether authorities in Italy or abroad have made arrests.
The case highlights a growing threat facing the financial sector: criminals are now able to combine social engineering with generative AI tools that can clone voices, fabricate video calls and produce convincing written instructions. Such techniques bypass traditional security checks that rely on human recognition or verbal confirmation. Banks have invested heavily in cybersecurity, but the human layer of authentication remains a weak point when attackers can convincingly impersonate trusted figures.
Fideuram operates as Intesa Sanpaolo's private banking arm, managing wealth for high-net-worth clients. The division's exposure to a single fraudulent instruction of this size suggests that internal approval processes may have been circumvented or that multiple employees were deceived simultaneously. The sources did not specify how the fraud was eventually uncovered or how long the transfers took to execute.
The incident is likely to intensify scrutiny of how banks verify large transactions, particularly when instructions appear to come from senior management. Regulators across Europe have been warning about the rising use of AI by criminal networks, and the European Union's forthcoming AI Act includes provisions aimed at improving transparency and accountability for high-risk systems. However, the legislation focuses primarily on developers and deployers of AI, not on the criminal misuse of the technology.
For Intesa Sanpaolo, the reputational and financial fallout could be significant. The bank is a systemically important institution in Italy and a major player in European finance. While €95 million is a manageable sum relative to its balance sheet, the breach of trust and the apparent ease with which internal controls were defeated may alarm clients and investors. The bank has not yet indicated whether it will tighten authentication procedures or reimburse affected accounts.
The fraud also underscores a broader challenge for businesses beyond banking. AI-generated impersonation attacks have targeted companies in sectors ranging from manufacturing to technology, often resulting in wire transfers to fraudulent accounts. Security experts have long warned that voice and video deepfakes are becoming cheaper and more accessible, lowering the barrier for criminals. In response, some firms have introduced challenge-response protocols and multi-person authorisation for high-value payments.
Details of the Fideuram case remain limited, and it is not known whether the fraudsters were acting alone or as part of an organised network. The sources spoke on condition of anonymity because they were not authorised to discuss the matter publicly. Italian police and financial authorities have not issued statements. The lack of official confirmation leaves key questions unanswered, including whether the transfers were made in a single transaction or several, and which countries received the funds.
As banks continue to digitise their operations, the line between a genuine executive instruction and a synthetic imitation is becoming harder to draw. The Intesa Sanpaolo episode serves as a stark reminder that even the most established institutions can be caught off guard when technology is weaponised against them. For now, the focus will be on recovery, investigation and the lessons that other lenders must learn before the next attack.