On September 25, 2026, Reuters reported that fraudsters using AI to impersonate senior executives stole €95 million ($108 million) from Fideuram, the private-banking arm of Italy's Intesa Sanpaolo.
The attack worked because a WhatsApp message and one phone call were the entire authorization. That is exactly what a decision-gated payment system exists to catch.
The receipts
- February 2026: then-Fideuram chairman Paolo Molesini received a WhatsApp message appearing to be from Intesa Sanpaolo CEO Carlo Messina, seeking urgent help with an overseas transaction. (Reuters, Sept 25, 2026, citing two sources; first reported by Corriere della Sera.)
- The "confirmation": a follow-up phone call appearing to be from a senior law-firm partner — with the voice replicated by AI, per the sources.
- The money: Molesini instructed finance to arrange a series of transfers to foreign accounts, mainly in China and Hong Kong.
- The tally: €95M taken; €53M recovered through cooperation between authorities in China, Portugal and Italy; €36M still missing, converted into cryptocurrencies.
- The fallout: Molesini resigned as chairman in March citing personal reasons. Milan prosecutors have a foreign national living outside Europe under investigation for computer fraud. Intesa Sanpaolo declined to comment.
The structural failure
The "authorization" was one human's belief. Unverified channel + novel beneficiaries + manufactured urgency + zero independent confirmation. The "lawyer's confirmation" was ephemeral audio — there is no auditable record of who approved what.
Three days before this story broke, six global banks (Bank of America, Capital One, ING, NatWest, ASB Bank, Commonwealth Bank of Australia) published Building Trust in Agentic Commerce demanding exactly that: auditable records of instruction, authority, intent, and outcome.
The machine-native fix: the decision gate
Score every payment instruction before money moves:
state: instruction_channel=whatsapp_unverified, claimed_sender=CEO,
beneficiary=new_accounts_china_hk, independent_confirmation=none,
urgency=manufactured
gate: ≥0.80 execute · 0.50–0.79 hold for review · <0.50 block + escalate
→ deep in the <0.50 band → BLOCK, log, require human verification
through an independent channel (signed message, not another voice call)
We ran a scam-pattern instruction through our live gate this afternoon: POST scriptmasterlabs.com/api/harness/decide returned "no" at 0.8176 confidence — the gate auto-approved the refusal (HTTP 200, settlement: false; the harness only emits an authorization signal, it never moves money).
Three Monday-morning rules
- Unverified channel never executes alone. Any instruction arriving over an unverified channel requires independent-channel confirmation before money moves. Hard rule, not a suggestion.
- Score the instruction, not the voice. Channel verification, beneficiary familiarity, urgency flags, confirmation status. A familiar voice in 2026 is not a control.
- Keep a signed approval ledger — Legal Context Protocol style: who instructed, who approved, what happened.
Honest caveats: the harness demo is a hand-crafted state through a local heuristic (calibrated: false); it's a pattern demo, not proof it would have caught the real attack. TypeSafe's Jev isn't wired in yet.
This article originally appeared at https://scriptmasterlabs.com/intesa-ai-voice-scam — the canonical version with full receipts and FAQ.
Top comments (0)