A former chairman of Fideuram Bank, the wealth management subsidiary of Italy’s Intesa Sanpaolo, has fallen victim to an artificial intelligence-based fraud scheme that resulted in the unauthorized transfer of €95 million from the institution’s accounts. The incident, which unfolded through a manipulated WhatsApp message, represents a significant financial loss for one of Europe’s leading banking groups and underscores the evolving cyber-security threats facing the continent’s financial sector.
The former board chairman received what appeared to be a legitimate communication via WhatsApp, generated using artificial intelligence technology to mimic authentic business correspondence. Convinced of the message’s authenticity, the executive authorized the substantial fund transfer. Subsequent investigation revealed the fraudulent nature of the instruction, prompting immediate recovery efforts by the bank.
Partial Recovery and Significant Loss
Despite rapid intervention following the discovery of the fraud, Fideuram Bank and its parent company Intesa Sanpaolo were able to recover only a portion of the transferred funds. The incident resulted in a confirmed net loss of approximately €36 million, representing more than one-third of the total amount diverted from the bank’s treasury.
The case highlights a critical vulnerability in corporate banking operations: the susceptibility of senior executives to convincingly fabricated digital communications. While traditional cybersecurity frameworks have long focused on protecting against external network intrusions and malware-based attacks, this incident demonstrates how AI-generated content can circumvent conventional trust mechanisms within organizations.
Emerging Threats to European Banking
The Fideuram fraud occurs amid growing concerns among European financial institutions regarding artificial intelligence-enabled fraud techniques. Regulators and industry observers have increasingly warned about the potential for AI to generate convincing deepfakes and synthetic communications that exploit human decision-making processes, particularly among senior personnel authorized to approve large transactions.
The incident is unlikely to remain isolated. European banks have reported a marked increase in social engineering attacks leveraging AI-generated content over the past eighteen months. These schemes often target individuals with transaction authorization capabilities, circumventing technological controls by focusing instead on deceiving trusted decision-makers within the organization.
For Intesa Sanpaolo, Europe’s second-largest bank by assets, the episode presents both a financial setback and a reputational challenge, though the company’s substantial capital base and diversified operations limit systemic impact. The loss remains material but manageable within the context of the banking group’s overall financial performance.
The Fideuram case serves as a cautionary reminder that as artificial intelligence capabilities advance, European financial institutions must evolve their internal controls and authentication protocols beyond traditional verification methods. Regulatory bodies across the European Union are likely to intensify scrutiny of banks’ preparedness for AI-based fraud, potentially prompting updated guidance on executive authorization procedures and digital security frameworks for high-value transactions.