A major European bank has fallen victim to one of the most sophisticated scams in recent memory. Fideuram, a subsidiary of Italian banking giant Intesa Sanpaolo, lost approximately €39.5 million (around $41 million USD) after criminals used artificial intelligence to impersonate the bank’s own executives through a fake WhatsApp conversation and a cloned voice.
The incident, which was first reported by Italian newspaper Corriere della Sera, highlights a troubling new frontier in financial fraud where AI tools are weaponized against the very institutions meant to safeguard our money. For crypto investors and anyone holding digital assets, this case carries important lessons about social engineering attacks—the same type of scheme that frequently targets crypto holders.
How the Fideuram Deepfake Scam Worked
The attack followed a classic but AI-enhanced pattern known as social engineering. Criminals contacted Fideuram employees through a WhatsApp group that appeared to include senior executives from Intesa Sanpaolo’s leadership team. To make the deception convincing, the attackers used AI-generated voice cloning to mimic a top manager’s voice during a phone call.
Believing they were speaking with genuine executives, the employees were instructed to authorize several large transfers. By the time the fraud was discovered, roughly €39.5 million had already been moved, though some sources place the figure closer to €95 million depending on which transactions are included in the total. The bank is now investigating how the initial breach occurred and whether internal security protocols were bypassed.
What Is a Deepfake Scam?
A deepfake scam uses artificial intelligence to create realistic but fake images, videos, or audio recordings of real people. Voice cloning technology, in particular, has become alarmingly accessible. With just a few seconds of someone’s speech—often scraped from public interviews, earnings calls, or social media—criminals can generate a convincing clone of their voice.
Think of it like a photorealistic mask for sound: to the human ear, the cloned voice sounds identical to the original. In the Fideuram case, employees heard what they believed was their boss giving legitimate instructions, which removed one of the last psychological barriers that might have stopped the fraud.
Why Banks and Crypto Users Are Both at Risk
While this attack targeted a traditional bank, the crypto world is no stranger to deepfake fraud. In recent months, several high-profile crypto figures have had their likenesses hijacked to lure victims into fake investment schemes. Scammers have used AI-generated videos of Elon Musk, Vitalik Buterin, and other crypto celebrities to promote fraudulent giveaways and phishing sites.
Even crypto exchange executives have been impersonated. The common thread is always the same: tricking a human being into trusting a fake identity long enough to hand over money, credentials, or authorization.
Common Deepfake Attack Vectors in Crypto
- Fake video calls with supposed project founders or partners
- Cloned voices requesting urgent wallet access
- Synthetic social media accounts promoting fake token launches
- AI-generated livestreams announcing fraudulent airdrops
How to Protect Yourself from Deepfake Fraud
Whether you manage a bank’s treasury or your personal crypto portfolio, the defenses against deepfake scams are similar:
- Verify through a second channel. If someone contacts you via WhatsApp or video, hang up and call them back on a known, official number.
- Establish code words or verification protocols for any financial instructions, especially large ones.
- Use hardware wallets for crypto storage. Keeping your private keys offline makes it nearly impossible for remote scammers to drain your funds, even if they trick you into clicking something. A reliable option is the Ledger hardware wallet, which stores your seed phrase and signs transactions without ever exposing your keys to the internet.
- Be skeptical of urgency. Scammers almost always create a false sense of emergency to prevent careful thinking.
- Limit your public exposure. The more audio and video of you online, the easier it is to clone your likeness.
The Bigger Picture: AI and Financial Crime
The Fideuram case is unlikely to be an outlier. As generative AI tools become cheaper and more powerful, deepfake attacks will almost certainly increase across both traditional finance and the crypto industry. According to several cybersecurity firms, deepfake-related fraud attempts grew by more than 3,000% in some regions over the past year alone.
For everyday crypto users, this trend reinforces a principle that has always been true: no legitimate organization will ever ask for your seed phrase, private keys, or remote control of your wallet. If someone does—whether through a text, a call, or a convincing AI video—it is a scam, full stop.
Conclusion
The €39.5 million lost by Fideuram is a wake-up call for every institution and crypto investor. Deepfake technology has moved from Hollywood movie plots to real-world bank heists, and the tools to pull off such attacks are becoming more accessible by the day. The best protection is a healthy mix of technical safeguards—such as using a hardware wallet and trading only on trusted platforms like Kraken or Bitvavo—combined with human vigilance. Always confirm financial requests through a separate communication channel, and remember: when in doubt, slow down. Scammers thrive on urgency.



