A sophisticated impersonation scam targeting Fideuram has left investigators tracing tens of millions of euros across international bank accounts, payment platforms and Bitcoin wallets.
The fraud, which took place in February 2026, reportedly convinced senior executives at the Italian private bank to authorize nearly €95 million in overseas transfers after scammers impersonated high-ranking financial and legal figures.
Authorities managed to recover or block a large portion of the money, but later court documents placed the amount still missing at around €39.5 million.
Investigators have also traced at least €4 million through accounts in several countries before the funds reportedly reached a Canadian money-transfer platform and two Bitcoin wallets.
The case shows how AI-generated voices, fake messages and convincing documents can be combined into a highly coordinated social-engineering attack.
How did the Fideuram scam begin?
The fraud reportedly started on February 23, when then-Fideuram chairman Paolo Molesini received a WhatsApp message that appeared to come from Intesa Sanpaolo CEO Carlo Messina.
Fideuram is the private banking arm of Intesa Sanpaolo, Italy’s largest banking group.
According to Italian media reports and court documents summarized by ANSA, the sender claimed that a confidential acquisition involving an international bank was underway.
The supposed Messina allegedly told Molesini that Intesa could not carry out the transaction directly because information leaking to the market could cause Italy’s securities regulator, Consob, to intervene.
Fideuram was therefore presented as the entity needed to complete the transaction.
The message came from an unfamiliar number, but the attackers did not rely on WhatsApp alone.
Scammers allegedly used an AI-cloned voice
A second person then contacted Molesini while pretending to be Paolo Nastasi, managing partner of A&O Shearman Italia.
Nastasi was someone Molesini knew personally.
He had no involvement in the scam.
According to reports based on the investigation, the caller used an artificially generated version of Nastasi’s voice to make the impersonation more convincing.
The use of a familiar voice appears to have added credibility to the fraudulent request.
Fake emails designed to resemble communications from the law firm were also sent to support the story.
These emails reportedly contained foreign bank-account information and payment instructions.
Documents sent to Molesini included what appeared to be a confidentiality agreement and a special power of attorney carrying Messina’s signature.
Fraudsters targeted more than one employee
The attackers did not depend on convincing only one senior executive.
Investigators say Fideuram’s treasury and payments manager was separately contacted by someone pretending to be another senior company official.
The employee was allegedly told that Molesini would authorize a series of urgent and confidential transactions.
Using separate communication channels and impersonating multiple people helped reinforce the story.
This appears to have allowed the attackers to move large amounts of money before the fraud was detected.
Nearly €95 million was transferred abroad
Between February 23 and February 25, Fideuram reportedly sent 11 transfers totaling close to €95 million.
Significant amounts were routed to accounts in countries including China and Portugal.
Once the fraud was discovered, banks and law-enforcement agencies moved quickly to stop or recover some of the transactions.
Authorities were able to retrieve much of the original amount.
However, millions had already moved through additional accounts and payment channels.
How much money was recovered?
Different reports provide slightly different figures because they were published at different stages of the investigation.
ANSA reported that approximately €42 million transferred to China was blocked and returned.
Italian investigators also secured more than €13 million held at a Portuguese bank.
A Milan judge authorized the seizure in Portugal with assistance from local authorities.
Earlier reporting from Corriere della Sera placed the amount recovered from China at closer to €40 million.
Reuters later reported that approximately €53 million had been recovered overall, leaving around €36 million unaccounted for at that point.
More recent court documents cited by Italian media put the unresolved amount at approximately €39.5 million.
The variation reflects changes in the recovery process and the different dates on which the figures were reported.
How did some of the money reach crypto?
Investigators have reconstructed at least one path involving approximately €4 million.
According to Corriere, the funds moved through accounts in Malta, Luxembourg and the Netherlands.
They were then reportedly transferred through a Canadian money-transfer platform before reaching two Bitcoin wallets.
This chain shows how traditional banking accounts and crypto infrastructure can be combined in attempts to move stolen funds across jurisdictions.
Bitcoin itself does not make transfers invisible.
Blockchain transactions remain recorded on the public ledger.
However, identifying the people who control specific wallets can still require information from exchanges, payment platforms, banks and authorities in multiple countries.
Who controlled the Bitcoin wallets?
Investigators have linked the wallets to a person currently under investigation.
However, no court has yet established who ultimately controlled the funds or whether the identified individual participated directly in the original impersonation scheme.
That distinction is important.
Being linked to an account through which money passed does not by itself establish responsibility for planning or carrying out the entire fraud.
Authorities are still trying to reconstruct the full network behind the transfers.
A 48-year-old Israeli citizen is under investigation
Milan prosecutors are investigating a 48-year-old Israeli citizen who is suspected of being connected with the group involved in the fraud.
The individual has not been publicly named.
According to Corriere, the person was connected to one of the foreign accounts that handled approximately €4 million before the funds reached the Bitcoin wallets.
Investigators are still verifying whether the identity documents associated with the suspect belong to a real individual.
Authorities are also examining whether the identity may itself have been used to conceal the true people controlling the accounts.
International judicial requests are being sent to obtain information from banks, payment companies and crypto-related platforms.
Paolo Molesini is not under investigation
Former Fideuram chairman Paolo Molesini is not being investigated in connection with the fraud.
Reports also state that Fideuram has not initiated legal proceedings against him over the incident.
Molesini left his position in March.
Fideuram announced on March 12 that he had resigned as chairman of both Fideuram and Intesa Sanpaolo Private Banking for personal reasons.
Tommaso Corcos then assumed the chairman’s responsibilities.
The resignation came several weeks after the fraudulent transfers, but the company’s announcement did not publicly connect his departure to the scam.
AI made the impersonation more convincing
The Fideuram case demonstrates how modern fraud can combine several techniques at once.
Instead of relying on a single phishing email, the attackers allegedly used:
- WhatsApp impersonation
- AI-generated voice cloning
- Fake legal emails
- Forged-looking documents
- Multiple impersonated executives
- Overseas bank accounts
- Crypto wallets
- Urgent and confidential payment instructions
Each element supported the others.
A convincing voice can make a suspicious email appear legitimate.
An official-looking document can reinforce a fraudulent phone call.
And communication with multiple employees can make an invented transaction seem like a real internal process.
Why executive impersonation scams are dangerous
Senior executives are attractive targets because they can authorize large or unusual transactions.
Fraudsters often exploit urgency and confidentiality to discourage victims from following normal verification procedures.
A request supposedly involving a confidential acquisition, for example, may explain why employees are told not to discuss it widely.
That creates an environment where normal internal checks can be weakened.
AI-generated voices make these scams more difficult to detect because employees can no longer rely only on recognizing how someone sounds.
A familiar voice is no longer strong proof that the caller is really the person they claim to be.
Similar cases are being investigated in Italy
Milan prosecutors are reportedly examining other fraud cases involving similar combinations of executive impersonation, fake emails and AI-generated voices.
One separate case involved another bank manager who was reportedly tricked into authorizing nearly €24 million in transfers during May.
Around €20 million was later recovered.
Those funds were reportedly traced through countries including Spain, Singapore, Hong Kong and Bahrain.
Another case involving a smaller financial institution concerned around €2 million, with part of the money later recovered in Croatia.
Italian authorities have noted similarities in the techniques used across these incidents.
However, they have not publicly established that the same criminal group was responsible for all of them.
Crypto users have also faced AI impersonation scams
AI-based impersonation is increasingly appearing in cryptocurrency fraud.
Scammers have used deepfake videos and AI-generated voices to imitate crypto executives and convince victims to transfer digital assets.
Ripple users, for example, have been targeted by fraudulent videos pretending to feature company executives.
Those schemes attempted to persuade users to send cryptocurrency based on fake promotions or investment offers.
Binance founder Changpeng Zhao has also warned users about campaigns using AI-generated images and fake executive identities.
The technology lowers the cost of creating realistic impersonations and allows fraudsters to reproduce the appearance or voice of public figures at scale.
Bitcoin did not cause the initial fraud
Although part of the missing Fideuram money eventually reached Bitcoin wallets, the fraud itself began within the traditional financial system.
The attackers first convinced bank personnel to authorize conventional international transfers.
Crypto appears later in the money trail.
This distinction matters because describing the incident simply as a “crypto scam” would overlook how the fraud was actually carried out.
The core attack was social engineering.
The attackers allegedly manipulated people into approving legitimate-looking bank transactions through impersonation, urgency and forged communications.
Bitcoin then became one of several tools reportedly used to move part of the stolen money.
Blockchain records may help investigators
Moving stolen money into Bitcoin does not automatically end the trail.
Bitcoin transactions are publicly recorded.
If investigators can identify a wallet linked to the stolen funds, they can follow subsequent transfers onchain.
The harder part is linking blockchain addresses to real people or organizations.
That often requires cooperation from centralized exchanges, payment platforms and financial institutions.
If stolen funds reach a regulated exchange, investigators may be able to request customer identification and account records.
However, money can pass through numerous wallets and jurisdictions before authorities obtain that information.
International cooperation is central to the investigation
The Fideuram case involves accounts and services spread across multiple countries.
Investigators therefore depend heavily on cooperation between jurisdictions.
Italian authorities have already worked with foreign institutions to freeze and recover funds.
The remaining investigation requires information from banks, payment services and potentially crypto companies in other countries.
Authorities are trying to determine who opened the relevant accounts, who controlled them and where the funds moved afterward.
Italy has also tightened crypto transaction monitoring
Italy has separately strengthened requirements around cryptocurrency transfers.
The Bank of Italy has instructed crypto service providers to apply sanctions screening to transactions without minimum value thresholds.
That means compliance checks must apply even to relatively small transfers.
Those rules are separate from the Fideuram fraud investigation.
However, they reflect the broader regulatory focus on tracing digital-asset transactions and identifying the people behind them.
What happens next?
Investigators are continuing to follow the international money trail.
A major focus will be identifying the people who ultimately controlled the foreign bank accounts and Bitcoin wallets.
Authorities will also need to determine whether the currently identified suspect was involved in organizing the fraud or only appears later in the movement of funds.
Further cooperation with banks, payment companies, exchanges and foreign authorities could help clarify that connection.
The case also raises broader questions for financial institutions about internal verification.
AI voice cloning means companies can no longer treat a familiar voice as reliable proof of identity.
Large or unusual payments may increasingly require independent verification through trusted internal channels, regardless of how convincing a caller, email or document appears.
For Fideuram, authorities have recovered a significant share of the nearly €95 million initially transferred.
But approximately €39.5 million remains unresolved according to later court reporting, and investigators are still trying to determine exactly who controlled the money once it moved through foreign accounts and into crypto.
Disclaimer: This article is for informational and educational purposes only. Individuals mentioned as being under investigation are presumed innocent unless and until proven guilty in court.


































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































