Fraud and Artificial Intelligence

Voice cloning is the new frontier for evil geniuses

The cases involving Banca Fideuram, Banca Ifis and other high-profile victims highlight new and extremely serious risks for businesses

Criminalità informatica (Adobe Stock)

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

The case of Banca Fideuram and its (now former) chairman Paolo Molesini, as well as the case of the manager at Banca Ifis and that of the executive at a cooperative credit bank in the Milan area, all share a common feature: they are based on fraudulent deepfake schemes utilising advanced voice-cloning techniques.

Sound samplers

They work in the same way as the sound samplers used in recording studios. If a particular type of instrument is required for a track, the producer knows exactly which one to choose: do you need the mellow sound of a Steinway & Sons grand piano? The sample is there. Do you prefer the more defined sound of a Yamaha half-grand? That’s available too. It’s a sort of vast acoustic library. In the same way, the web represents an immense library of voices and images. The perpetrators of the massive frauds carried out against certain banks (and others) extracted and sampled the voices of the direct superiors of the employees involved, tricking them into doing things they would never have done otherwise. And as long as this is carried out using WhatsApp voice messages (such as the voice messages falsely purporting to be from the CEO of Intesa Sanpaolo), a person of sound mind would never fall for it. The real breakthrough lies precisely in the use of voice conversion or speech-to-speech software, which allows fraudsters to speak on the phone using their own voice, whilst the person on the other end hears a different one. These are voice-altering devices that usually cause the victim to let down their guard completely.

Loading...

The Moratti-Crosetto case

After all, this is exactly what happened to Massimo Moratti in the scam involving the fake phone call that Defence Minister Guido Crosetto never actually made. Add to this the sending of skilfully forged documents bearing the correct signatures (which are usually easy to find in company financial statements), and the danger posed by this scheme becomes devastating. What happened at Banca Fideuram? The impostor posing as Messina used a WhatsApp voice message to inform Molesini in advance of a phone call from a lawyer to finalise and conclude the acquisition of an international bank. The lawyer actually exists and is someone well known to Molesini (which speaks volumes about the level of preparation that went into the scam).

Fraud in stages

In reality, it is a cloned voice generated by artificial intelligence. The lawyer sends eleven documents and gets Molesini to sign a confidentiality agreement and a special power of attorney, apparently also signed by Messina. Bank details are then provided, and the banker arranges a total of 11 bank transfers amounting to over 95 million euros, initially directed to accounts in China and Portugal. Part of the sum has already been recovered, but 39.5 million is still missing. More than 36 million is believed to have passed through accounts in Malta, then in Luxembourg and the Netherlands, before moving to a Canadian money transfer platform and finally into two cryptocurrency wallets linked to the sole suspect, an Israeli national.

Look for the money

This is where the search for the money begins, and the specialists at Decripto and Indago Labs have already started tracing the official channels used by the gang. Giorgio Scura, founder of Decripto and Indago Labs, says he is certain of two things: “Firstly: in my view, this is a single organisation. Secondly, we have a feeling that the cases that have come to light are not the only instances of companies being targeted.” Why? “Our analysis starts with two addresses: one on the Tron blockchain and one on Ethereum, which we extracted by cross-referencing the blockchains with our databases. These were probably the recipients of some of the funds associated with Fideuram. The first wallet we analysed was the one on Tron. The address has been active since September 2025 and has since processed nearly 90 million USDT.”

There are probably other victims

It is therefore not an address set up for a single transaction. Rather, it is a criminal infrastructure that has been operating for months and has, in all likelihood, also been used for other activities. This suggests that there may well be other victims.” Scura continues: “The addresses receiving funds from the Tron wallet form a cluster with the characteristics of one or more OTC (over-the-counter) trading platforms, where stablecoins and cash change hands outside regulated exchanges. This profile is consistent with that of two operators, Huione and Xinbi Group, the two names synonymous with international money laundering. Huione Group, a Cambodian conglomerate, was designated by the US FinCEN (Financial Crimes Enforcement Network) as an institution of primary concern for money laundering, after receiving over 39.6 billion dollars in 2025 alone. Xinbi Guarantee was sanctioned by OFAC (Office of Foreign Assets Control) on 9 September 2026.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti