Investigation into Fraud Scheme
An investigation has revealed a complex fraud scheme that led to a staggering loss of at least €39.5 million for Fideuram, which operates as Intesa Sanpaolo’s private banking arm. This elaborate scam, which took place in February 2026, saw funds diverted into Bitcoin wallets after a series of impersonation calls and messages targeting the bank’s then-chairman, Paolo Molesini.
Details of the Fraud
The fraudulent activity commenced on February 23, when Molesini received a WhatsApp message that claimed to be from Carlo Messina, the CEO of Intesa Sanpaolo. Although the number was unfamiliar to him, the message proposed a high-stakes acquisition involving another international banking entity. Under the guise of confidentiality, the purported Messina claimed that direct purchases could not occur due to risk of exposure to Italy’s financial regulatory body, Consob.
A call, allegedly from lawyer Paolo Nastasi, who Molesini recognized, also took place. However, it was later determined that Nastasi had no part in the crime, with reports indicating that the fraudsters utilized artificial intelligence to replicate his voice.
Throughout the scheme, Molesini received fabricated documents and communication resembling that of legitimate legal counsel, which included payment instructions and supposed banking information. A significant part of the deception involved simultaneous communications. The head of Fideuram’s treasury department received calls from someone posing as a senior executive, reinforcing the narrative that Molesini would authorize confidential payments urgently.
Execution of Transactions
Between February 23 and February 25, a total of 11 transactions, amounting to nearly €95 million, were executed, with funds funneled to various foreign accounts in China and Portugal. Fortunately, Fideuram’s detection system allowed for the prompt interception of a portion of these transactions. Reports indicate that authorities managed to recover about €55 million overall, with €42 million recovered from China and €13 million from Portugal, after the involvement of a Milan judge who cooperated closely with local authorities.
Ongoing Investigations
Investigators have recently detailed that out of the unresolved €39.5 million, a portion had unexpectedly transited through foreign accounts and into cryptocurrency before banks were able to intervene. They successfully traced a chain where around €4 million moved through several countries including Malta and Luxembourg before arriving in two Bitcoin wallets, which are now linked to an individual under investigation.
The suspect, a 48-year-old Israeli citizen, has been preliminarily tied to the accounts linked to these funds, although his full role in the scheme has yet to be clarified. Authorities are also working to confirm the authenticity of identity documents related to this individual, probing whether they represent a genuine individual or another layer of identity masquerading the real perpetrator.
Consequences and Broader Implications
Molesini has since resigned from his positions at both Fideuram and Intesa Sanpaolo Private Banking, officially for “personal reasons,” several weeks following this incident. Importantly, he is not under scrutiny in relation to the scam, as Fideuram has not pursued any legal action against him.
The incident is part of a worrying trend of fraud using advanced impersonation techniques, including AI-generated voices. Italian investigators are simultaneously examining other similar fraud cases, including one that involved nearly €24 million in unauthorized transfers and another that pertained to approximately €2 million associated with a smaller bank. These incidents, characterized by their use of social engineering, have raised alarms about the vulnerabilities of banking institutions to such digital deceptions.
Regulatory Response
In light of these threats, Italy has intensified oversight of cryptocurrency transactions to enhance compliance and mitigate risks associated with fraud. The Bank of Italy has mandated that crypto service providers must conduct comprehensive sanctions screening on all transfers, regardless of their value, aiming to bolster the integrity of financial transactions in the crypto space.