AI Fraud Strikes: How €95 Million Was Taken from Intesa Sanpaolo and What Banks Must Do Next

A reported theft of about €95 million from Intesa Sanpaolo’s private banking operations highlights a new breed of financial crime powered by artificial intelligence. While official details remain limited, available signals point to AI-enabled social engineering and automation that magnified scale and speed.

The Incident: How AI Enabled the Heist

Public reporting offers few specifics, so analysts reconstruct a likely sequence. Attackers probably combined deepfake audio or synthetic identities with highly targeted spear-phishing to impersonate clients and wealth managers. AI models can generate believable voice and text, craft messages that bypass human scrutiny, and automate account takeover attempts at scale. In parallel, automated scripts may have structured transactions to mimic normal flows and exploit timing gaps in manual review processes.

Broader Implications for Banking Security

This event shifts the threat landscape. AI gives criminals tools to perfect impersonation, bypass rules-based controls, and find blind spots in transaction monitoring. Consequences include regulatory scrutiny, client losses, reputational fallout, and higher compliance costs. Smaller signals that once flagged fraud can be drowned out by AI-generated noise, making traditional rule sets less reliable.

Strengthening Defenses Against AI-Powered Threats

  • Adopt layered authentication combining hardware tokens, adaptive MFA, and biometric checks for high-risk actions.
  • Deploy anomaly detection models trained on adversarial scenarios and refreshed to reflect new attacker behavior.
  • Use deepfake detection tools for voice and video, and apply strict verification protocols for transaction authorizations.
  • Conduct red-team exercises that simulate AI-assisted attacks and harden response playbooks.
  • Share intelligence across institutions and with regulators to accelerate detection of emerging tactics.

Key Takeaways for Financial Leaders

  • Treat AI-driven fraud as an operational risk that touches technology, controls, and client relations.
  • Invest in continuous model validation and adversarial testing to keep detection aligned with attacker methods.
  • Prioritize fast response processes for disputed transfers and strengthen KYC and approval workflows.

The Intesa Sanpaolo case is a warning: AI multiplies attackers’ capabilities, and banks must close gaps across people, processes, and systems to reduce exposure.