On 23 February 2026, the chairman of an Italian private bank got a WhatsApp message from a number he did not recognise. It appeared to come from the chief executive of the group that owns his bank. The group was buying an international bank, it said, and the money would have to move through his bank. Absolute secrecy was essential: if it leaked, Italy's market regulator would get involved and the deal would die. A lawyer would be in touch.
The lawyer called. The chairman knew him - a senior partner at a large international firm, a man he had dealt with before. He recognised the voice.
He was right to. It was that lawyer's voice. It was also a copy, generated by AI, and according to the Italian reporting the lawyer had no idea any of it was happening.
Over the next three days, about EUR 95 million left the bank.
I want to be useful rather than alarming, so here is the shape of what follows. First, how the trick actually worked, because almost every retelling has one detail backwards and that detail is the whole mechanism. Then what the research says about your chances of hearing a fake - they are worse than you think, and worse in a direction nobody warns about. Then the practical part: what to do tonight, what to say on the phone, and how to have this conversation with a parent. The statistics come last, because the most interesting thing about them is that they barely exist.
The detail almost every retelling got backwards
A great many headlines said the fraudsters cloned the chief executive's voice.
They did not. Carlo Messina, the chief executive of Intesa Sanpaolo - Italy's largest bank, and the owner of the bank in this story - was impersonated in writing only, by WhatsApp messages from a number that was not his. The voice on the telephone belonged to someone else entirely: a lawyer the chairman knew personally. Italian financial papers name him. Reuters chose not to, and neither will I, because he did nothing at all except have a recognisable voice. He is a victim here, not a participant, and I have found no public statement from him or his firm.
This is not a pedantic correction. It is the mechanism.
A text message from your boss is easy to doubt. You might check the number. But the text does not have to convince you on its own - it only has to set up the call. And the call does not come from the boss, whose voice you would listen to carefully, but from a third person whose entire role in the story is to confirm what the boss said. By the time you hear a voice you recognise, you are no longer asking "is this really him?" You are asking "does this check out?"
And it does, because two separate people are telling you the same thing.
They were not separate. That was the trick, and you can see the same shape in frauds that have nothing to do with AI at all - we will come back to that.
Three days, not one urgent phone call
The warning everyone has heard is about a single panicked call. That is not what this was.
Italian reporting based on the investigation file describes eleven documents sent to the chairman on what appeared to be the law firm's letterhead. The accounts of what those documents were do not agree: the news agency ANSA describes them as including a confidentiality agreement and a power of attorney attributed to the chief executive, while the newspaper Il Fatto Quotidiano describes all eleven as separate payment instructions. The reporting also says the manager responsible for the bank's payments got his own call, warning him in advance that urgent and confidential transfer orders were coming - so that when they arrived, they felt expected rather than alarming. Reuters does not carry that detail; it comes from Italian papers reading the court file.
The money went out between 23 and 25 February, reportedly in eleven transfers, mainly to accounts in China and Hong Kong, with a first leg to Portugal. Some retellings compress this into "a single afternoon". The dated reporting describes three days. Nothing stopped it while it was going out.
That is the shape worth remembering: not one call, but a story in layers, each one making the next easier to believe. A Swiss case reported by public broadcaster SRF in January 2026 goes further in the same direction - a businessman transferred several million francs after roughly two weeks of calls in which manipulated audio impersonated a trusted business partner. Two weeks.
So the advice "hang up if they rush you" has a blind spot, and the blind spot is patience. Hold that thought; the replacement for it is three sections down, and it is better.
Can you hear it? The research is blunt: no
The standard advice is to listen for something off - a flat tone, odd phrasing, a strange rhythm. It is in the FBI's own alerts. It is on an infographic the American Bankers Association Foundation published with the Bureau. It is the first thing anyone says.
The published research does not support it.
The largest peer-reviewed listening study is titled, without hedging, "Warning: Humans cannot reliably detect speech deepfakes". Across 529 listeners, people identified synthetic clips correctly 73% of the time and genuine ones 67.8% - about 70% overall. In plain terms: roughly three times in ten, you get it wrong. Training people with examples first improved them by under four percentage points. The authors conclude that trying to make humans better at this is unrealistic. One limit worth stating: the voices were generic synthetic speech, not clones of people the listeners knew, so this measures ear-based detection in the abstract.
A 2025 study used clips made with an ordinary commercial cloning product and 604 listeners. They correctly flagged a clone as artificial 60.8% of the time. One in five did no better than a coin toss on the clones. Asked whether a clone and a real recording were the same person, they said yes in a median 83.3% of trials.
Two findings in that study cut against everything intuition tells you. **Longer clips were more likely to be taken for the real person. So were clips of ordinary scripted speech.** A longer call is not a safer call. On that evidence, extra time on the line is not working in your favour - which is exactly backwards from how most people think they would handle it.
There is an honest tension in the official advice, and it is better to see it than to be given a tidy answer. In a May 2025 alert, the FBI wrote that "AI-generated content has advanced to the point that it is often difficult to identify" - and, in the same document, told readers to listen closely to tone and word choice to spot a cloned voice. Both sentences, one document. The evidence backs the first one.
What about software that detects fakes? The clearest official statement comes from the US Federal Trade Commission, summarising its own Voice Cloning Challenge in a 2024 filing: "Early investigation has revealed widely varying notions about how effective voice cloning detection solutions may be. However, voice cloning itself is rapidly improving and becoming easier to use." A 2025 system from Intel Labs, built specifically to cope with voices it has not met and which its authors say beats the best single system in a major detection challenge, scored an equal error rate of 0.43% on its own test set - about one wrong call in 230 - and between 3.19% and 7.82% on audio from elsewhere. That is progress, not failure. But even the improved case gets roughly one in twenty wrong once the audio is unfamiliar, and that is on clean research recordings, not a phone call.
Europol's 2022 report on deepfakes names the structural problem: detectors are trained on databases of known fakes, so nobody knows how they will do against a new generator - and whoever makes the fakes can simply retrain it to stop producing whatever the detector looks for. Its analysis is mostly about images and video, but the mechanism is the same.
As for how little of your voice is needed: the "three seconds" figure everyone repeats comes from a 2023 Microsoft research paper, which reported synthesising personalised speech from "a 3-second enrolled recording of an unseen speaker". The honest version is three seconds of you, on top of a model trained on 60,000 hours of everybody else.
The one that failed, and the single question that stopped it
In July 2024 someone tried almost exactly this on Ferrari.
The approach was near-identical: WhatsApp messages from a number that was not the chief executive's - "Hey, did you hear about the big acquisition we're planning? I could need your help", then "Be ready to sign the Non-Disclosure Agreement our lawyer is set to send you asap". A confidential deal. A currency hedge. Then a call in a voice that sounded like CEO Benedetto Vigna.
The executive on the other end asked what the title was of the book Vigna had recommended to him a few days earlier.
The call ended. Ferrari lost nothing.
Notice what did not happen. He did not detect anything. He did not catch a robotic tone or a strange cadence - and nothing in the listening research gives any reason to think he could have relied on hearing one. He asked for something the caller could not produce - a fact that existed only between two real people.
That is the whole answer, and it is why the practical section below never asks you to judge a voice.
What to do - for your family first
**The one sentence to have ready.** You do not need to accuse anyone or work out whether a voice is real. You need a sentence you can say while someone is crying at you:
> "I'm going to hang up and call you straight back on the number I have."
Then do it. Say it calmly, say it to everyone, and never apologise for it. If the caller argues, objects, says there is no time, says their phone is broken, says you mustn't tell anyone - that is the answer. A real relative in real trouble will be relieved you called back. A callback costs a legitimate caller two minutes.
This is the FTC's advice almost word for word: "Don't trust the voice. Call the person who supposedly contacted you and verify the story. Use a phone number you know is theirs." If you cannot reach them, the FTC says to try another relative or a friend of theirs.
**A family code word.** The FBI recommends one in as many words: "Create a secret word or phrase with your family to verify their identity." The FTC says nothing about code words at all - it is silence, not disagreement, but you should know that the advice is not universal.
If you set one, a few things make the difference between a code word that works and one that does not:
- Not a birthday, a pet, a street, a school or a maiden name. Anything findable on social media is not a secret. - Two unconnected words are better than one. Easy to say under stress, hard to guess. - Agree it out loud, in person. Not in a message, not in email, not in a notes app that syncs. - Everyone who might get the call needs it - including the grandparents, who are the ones who will be called. - Agree now what happens if someone forgets it under stress: you hang up and call back. The code word is a shortcut, not the only gate.
**The conversation with a parent or grandparent.** This is the part most articles skip, and it is the part that matters most, because the people targeted by these calls are rarely the people reading about them. What tends to work:
- Lead with the bank fraud, not with them. "A bank chairman in Italy fell for this, and about 95 million euros left his bank" removes any suggestion that falling for it means being foolish. It does not. He had every reason to believe what he heard. - Be specific about the script: a grandchild in an accident, arrested, needing bail; a second person who claims to be a lawyer or an officer; and an instruction not to tell anyone else in the family. - Give the rule, not the theory. One sentence: if anyone calls asking for money urgently, hang up and call back on a number you already have, no matter who they say they are. - Agree the code word there and then, while you are in the room. - Say explicitly that you will never be angry about a callback, and that no real emergency is ever made worse by two minutes.
**If money has already gone.** Act in this order, and act immediately, because speed is the only thing that matters:
- Call your bank's fraud line now, not tomorrow, and use the number on your card or in the bank's own app. Ask them to attempt a recall of the payment and to freeze anything pending. - Report it to the police. In the US, file with the FBI at ic3.gov and with the FTC at reportfraud.ftc.gov; in the UK, Action Fraud, or Police Scotland on 101 if you are in Scotland; elsewhere, your national fraud reporting body. - Write down everything while it is fresh: the numbers that called, the times, the names used, the account details you were given. - Do not let embarrassment slow you down. In the Italian case a bit over half the money was blocked or returned, through cooperation between authorities in Italy, Portugal and China - though who stopped what is reported differently by different outlets. - Be realistic, but do not assume it is hopeless. Bank transfers are sometimes recalled or frozen, and in the Italian case money was still being returned weeks later; UK Finance reports that 80% of losses to criminals posing as police or bank staff were returned to victims in 2025. Cryptocurrency and gift cards are a different matter: once sent, they are rarely recovered.
**Should you hide your own voice?** No. A voicemail greeting, a video, a voice note - the research above built clones from short recordings, and that ship sailed years ago. Nothing about your defence should depend on your voice being secret, which is precisely why the methods above do not.
What to do - if you approve payments at work
The controls that stop this are not new and are not technical. The FBI set them out in 2017, when business email compromise had already cost $5.3 billion worldwide. Its guidance was to establish other channels, such as telephone calls, to verify significant transactions; when calling back, to use previously known numbers rather than the numbers provided in the request; and to verify changes to payment details with a secondary sign-off by company personnel.
Callback on a number you already hold. A channel the attacker does not control. A second human who has to agree. Nine years old - and no published account of the Milan case says what its payment process actually required, because the bank has said nothing. What the reporting does establish is that nothing stopped the transfers while they were going out.
Add one thing the FBI did not have to think about in 2017: a pre-agreed challenge for anything that arrives outside the normal process. The Ferrari question works because it cannot be researched. A shared memory, an in-joke, something that happened in a room. Decide in advance that asking it is normal and that nobody senior will take offence.
And treat **urgency plus secrecy** as the signal itself - not as something to weigh against how convincing the caller sounds, but as the thing that ends the conversation. Every case in this article whose script is documented contains it. The Milan fraud dressed its secrecy up in a regulator's name. The grandparent scams call it a gag order. It is the one element no legitimate request ever needs.
What will not save you: the EU's Instant Payments Regulation, Regulation (EU) 2024/886, has since October 2025 required providers of euro transfers to offer a free Verification of Payee check, matching the beneficiary's name against the account number. It catches money sent to an account in the wrong name. It does not catch a correctly identified executive, properly authenticated, authorising a payment to an account whose details arrived as part of the deception. It would not have stopped this.
The uncomfortable part: the old version still works fine
In February 2025, a grand jury in Vermont indicted 25 Canadian nationals over call centres near Montreal that, prosecutors allege, took more than $21 million from elderly people in over 40 states. The script: a caller posing as the victim's grandchild, arrested after a car crash and needing bail money; then a second person posing as a lawyer; an instruction not to tell anyone; and finally someone who came to the house to collect cash. These are allegations, not convictions.
In December 2025, police in Regina announced charges in a grandparent-fraud case with six victims and more than C$40,000 taken. Same script. The release does not mention AI at all.
Look at what those scripts contain: two voices confirming each other, a reason not to check with anyone else, and time pressure. Exactly the structure that moved EUR 95 million out of an Italian bank. The Italian fraudsters had a chief executive by text and a lawyer by voice; the Montreal call centres had a grandchild and a lawyer. The second voice is the load-bearing part, and it has never needed to be synthetic.
This is why "AI fraud is exploding" is the wrong frame. The persuasion architecture is decades old and works with no technology at all. What AI changes is cost and reach: the second voice is now free, instant, available in any language, and it can be a voice you personally recognise instead of a stranger claiming a role. That is a real escalation. It is not a new crime, and treating it as a technology problem points you at the wrong defence.
How big is this really? Nobody is counting
I went looking for the number - how much AI voice cloning costs the world each year. It does not exist.
The most careful attempt at measuring how common this is comes from the Association for Financial Professionals, which surveyed 465 US corporate finance staff in January 2026, in a survey underwritten by the bank Truist and answered by self-selected respondents, all American. Three quarters had faced attempted or actual payments fraud. Only 6% reported a confirmed deepfake incident - and 40% said they did not know whether they had been targeted at all.
That 40% is the honest answer to "how common is this?" Nobody knows. Including the people it would have happened to.
The official statistics bear that out, agency by agency. The FBI publishes exactly one figure specifically about cloning a family member's voice: victims "claimed losses over $5 million in 2025 to distress scams", in a year when the same report logged $20.9 billion in total losses. Its much-quoted "AI related" tally - 22,364 complaints, $893 million - means only that the victim mentioned AI somewhere in the report; the FBI defines the tag as meaning the complaint "contains a reference to artificial intelligence", and says itself that many victims "do not realize the extent AI may be involved in scams". The FTC's $3.5 billion in imposter-scam losses for 2025 does not mention AI once, and its detailed data book has no AI field anywhere.
Outside the US it is the same picture or stranger. UK Finance measures impersonation fraud carefully, and losses to criminals posing as police or bank staff fell 18% in 2025, to GBP 55.5 million, the lowest in the six years it publishes - with no category at all for someone impersonating your family, and no number attached to AI. Australia's 49-page national scam report has no voice-cloning category whatsoever; AI appears once, unquantified. Europol's 2026 assessment describes "AI-assisted impersonation" and voice chatbots used to pre-screen victims "at industrial volume", and attaches no figure to any of it.
So the technique is documented by everyone and measured by no one. Which means almost every large frightening number in circulation came from somewhere else - a survey commissioned by a company selling protection, or a projection. The famous $40 billion-by-2027 figure is a scenario built from expert scoring, not a measurement, and its starting point is total fraud losses rather than deepfake losses. Treat all of them, including any you see quoted next week, as marketing until shown otherwise.
Where the Italian money went, and where the case stands
Reuters reports that more than half was recovered - about EUR 53 million - through cooperation between authorities in Italy, Portugal and China, and that around EUR 36 million remains unaccounted for. Il Sole 24 Ore itemises it: about EUR 40 million identified, frozen and returned by a Chinese institution, and about EUR 13 million seized in Portugal. ANSA, citing the court file, puts the missing sum at EUR 39.5 million and the recovered total above EUR 55 million; the newspaper Open reaches EUR 59 million.
None of those sets adds up to EUR 95 million, and nobody has publicly reconciled them. I am not going to do the subtraction and hand you a tidy ledger, because the sources do not support one. What can be said: about EUR 95 million left, a bit over half was blocked or returned, and between EUR 36 and EUR 39.5 million is gone, converted into cryptocurrency.
Investigators have reconstructed one chain in detail, and it covers about EUR 4 million - the slice traced to the single person under investigation. Corriere Milano reports that it moved through accounts in Malta, Luxembourg and the Netherlands, then a Canadian money-transfer platform, and finally into two Bitcoin wallets. Milan prosecutors are working through international judicial cooperation to freeze the rest before it is cashed out.
One person is formally under investigation, described by Reuters as a foreign national living outside Europe, suspected of computer fraud. In Italy that is neither a charge nor a conviction, and as of early October 2026 there has been no arrest, no indictment and no confirmed extradition request.
And one thing that needs saying plainly, because a story like this invites the wrong inference. Paolo Molesini, the bank's chairman at the time, is the victim. Reuters reports that neither he nor any other executive there is under investigation. He resigned on 12 March 2026, some two weeks after the transfers and months before any of this became public; the stated reason was personal, and no source establishes a link.
What this story is actually about
Nothing was hacked. The bank has said nothing about how its controls behaved, and I have found no police or regulator statement; what the reporting establishes is narrower, and it is enough - nobody broke in, no system was breached, and nothing stopped the transfers while they were going out. The money moved because people with the authority to move it were persuaded, and the persuasion was good.
The technology was the cheapest part of it. The expensive parts were research - knowing who the chairman trusted, what a plausible acquisition would look like, which regulator to invoke - plus patience, and the discipline to warn the payments manager in advance so the orders would feel routine. The voice was the last component, not the thing that did the work.
So the conclusion is narrower than "AI can fake voices now, be afraid". It is this: **a voice is no longer evidence of identity, and your ear will not tell you when it stopped being one.** That change is permanent, and it is also completely survivable, because the defence was never your ear. It is one sentence - "I'll call you back on the number I have" - and the willingness to say it to someone who sounds exactly like your daughter.
A bank chairman with a lawyer he knew on the line could not tell. I would not bet on my own ear either. That is not a failure of attention, and it does not need to be fixed. It needs to be worked around, and working around it takes about two minutes and one phone call.
Sources, and the limits of this article
Everything about the Italian case comes from Corriere della Sera's report of 25 September 2026 - which sits behind a paywall and reaches this article through others - Reuters' confirmation the same day citing two people familiar with the matter, and later coverage in ANSA, Il Sole 24 Ore, Milano Finanza, Sky TG24, Open and Il Fatto Quotidiano drawing on the Milan seizure order. Intesa Sanpaolo and Fideuram both declined to comment, and I have found no public statement from either since. I have found no police or regulator statement, and there is no bank statement and no verdict. Every figure comes from investigation papers and unnamed sources.
Three things are genuinely unsettled. The published recovery figures do not reconcile. A minority of Italian outlets report that the chief executive's voice was cloned rather than the lawyer's - Reuters, Il Sole 24 Ore and Milano Finanza say the lawyer, and that is the account followed here. And as of early October 2026 the case has gone quiet: no arrest, no charge, no new seizures reported.
The statistics come from their primary sources: the FBI's 2025 Internet Crime Report and its 2017, 2024 and 2025 public alerts; the FTC's 2025 fraud release, its 2024 Consumer Sentinel data book and its 2024 filing to the FCC; UK Finance's 2026 fraud report; Australia's National Anti-Scam Centre report for 2025; Europol's IOCTA 2026 and its 2022 deepfake report; the Association for Financial Professionals' 2026 payments fraud survey; Deloitte's Center for Financial Services; research papers from Intel Labs and Microsoft Research; and the peer-reviewed listening studies in PLOS ONE (2023) and Scientific Reports (2025). The FTC's consumer alert on voice cloning and the infographic the American Bankers Association Foundation published with the FBI are quoted directly, as is Regulation (EU) 2024/886, the EU's Instant Payments Regulation. The Ferrari attempt is from Bloomberg's reporting via Fortune, the Vermont and Regina cases from the US Attorney's Office and the RCMP, and the Swiss case from SRF via trade coverage. Where a number comes from a survey commissioned by a company selling a product, it is labelled as such in the text, because that difference matters more than the number does.