TL;DR
AI-cloned voices were used to steal €95 million from Italy's largest bank, Intesa Sanpaolo, marking one of the largest AI-enabled financial frauds on record.
What happened
- €95 million was stolen from Intesa Sanpaolo, Italy's biggest bank by assets, via an AI voice-cloning scam.
- Fraudsters used AI-generated voice impersonation to deceive bank staff or clients into authorizing large transfers.
- The event was reported around September 25, 2026, placing it among the most consequential AI fraud cases in European banking history.
- Intesa Sanpaolo is a systemically important institution, making the breach a signal event for the entire European financial sector.
Why it matters
- €95 million in a single operation demonstrates that AI voice fraud has crossed from nuisance to systemic financial risk.
- Voice authentication, widely used by banks as a security layer, is now effectively compromised as a standalone control.
- Regulators across the EU will face immediate pressure to mandate liveness detection and multi-factor verification beyond voice biometrics.
- The attack raises liability questions: if AI tools can clone any executive or client voice, banks bear new operational risk that existing frameworks do not price.
- Competitors and insurers will reprice cyber and fraud coverage for institutions relying on voice-based authorization.
What to watch next
- Whether Italian and EU regulators (Banca d'Italia, EBA) issue emergency guidance on voice authentication standards in the weeks following the breach.
- Whether Intesa Sanpaolo recovers any funds and names the technology or threat actor involved, which would sharpen the industry's defensive response.
- Broader adoption of anti-deepfake voice verification vendors (liveness detection, adversarial audio detection) as banks scramble to patch the gap.
Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.