Blog

Bank fraud with voice clones: treat identity, channel and payment order as separate claims

Milanese investigations into AI fraud at banks show why identity, communication channel and payment order must be verified separately through an independent channel.

· By

A wooden desk with a printed payment order, a black landline telephone with the handset off, and an open card index of contact cards arranged in a row.
Identity, channel and payment order must each be confirmed separately through an independent, previously known channel.Image: IamVera.ai — original editorial illustration

Treat identity, communication channel and payment order as three separate claims that each require confirmation through an independent, previously known channel. Never trust a voice, email address or chat conversation as proof of authority, link dual control to transaction monitoring, and escalate suspicious cases immediately to fraud, AML and security teams.

The trigger is a report from the news agency ANSA of 25 September 2026: the Public Prosecutor's Office in Milan is investigating two new suspected frauds against banks in which AI-generated messages, emails and voice clones were used. In one case a bank manager is said to have authorised transfers totalling roughly 24 million euros as a result, and in another roughly 2 million euros. According to ANSA, the money moved through several countries and these cases are unrelated to the earlier Fideuram investigation.

In our assessment, a central control weakness may be overreliance on a single identity signal rather than independent confirmation. A credible voice, a plausible email address or an ongoing chat conversation was treated as proof that an authorised person was giving an order. That is precisely the point where AI amplifies the attack: it makes that one signal more convincing and cheaper to produce.

Why does AI in particular amplify this form of bank fraud?

AI can go beyond classic phishing by making the imitation of a specific person more convincing and, in the reported Milan cases, allegedly helping elicit human authorisation. The European supervisory authorities EBA, EIOPA and ESMA describe in their joint publication of December 2025 how AI makes online financial fraud more convincing through impersonation, deepfakes, AI-written phishing, synthetic profiles and imitation bank websites.

That this does not stop at individual swindles is confirmed by Banca d'Italia. The central bank warned on 10 September 2026 about deepfake videos imitating the image and voice of governor Fabio Panetta to promote fraudulent investment platforms. The lesson we draw from this: visual or vocal credibility must never count as proof of authority.

Which verification chain breaks an AI-imitated order?

We translate the supervisors' recommendations and the UIF's technical-indicator guidance into a proposed four-step control model: each relevant claim should be confirmed separately where practicable.

  1. Verify the sender through an independent channel. Call back on a previously known number or use an internal system, never the contact details from the suspicious message itself.
  2. Require dual control and out-of-band confirmation for unusual beneficiaries or high amounts, so that one employee cannot release the payment alone.
  3. Combine transaction monitoring with technical signals such as device fingerprint, IP address, geolocation, the beneficiary's history and the speed of the payment.
  4. Preserve evidence and escalate quickly to fraud, AML, security and investigation teams. The EBA, EIOPA and ESMA explicitly advise pausing before an urgent transfer and contacting the bank directly after a suspicion arises.

The idea of checking claims step by step for existence and support is useful here: identity, channel and order are each a claim that requires separate evidence. If this involves customers' personal data, the relevant GDPR obligations and national data-protection requirements must be assessed for the technical signals and evidence items, including purpose, necessity, proportionality, legal basis and retention.

Why must fraud prevention and AML work as one chain?

The Financial Intelligence Unit UIF of Banca d'Italia published a communication on 8 June 2026 stating that fraud-related suspicious transaction reports exceeded 30,000 in 2025. The UIF names generative AI, realistic deepfakes, fictitious or synthetic identities, instant payments, virtual IBANs and money muling as features of technology-facilitated fraud, and recommends having anti-fraud and AML functions work together and analysing technical indicators such as IP addresses, VPNs, device fingerprints and geolocation.

The open question the sources leave unaddressed is, in our assessment, the pace. In our assessment, AI-assisted social engineering can compress the time available for review, while cooperation between departments and analysis of technical signals may introduce operational delay. Organisations that have not established rapid transaction-intervention and reporting chains in advance may lose valuable time when intervention could still limit the damage. That means that combining cybersecurity and privacy within one AI governance is not theory but an operational condition. Analysing IP addresses, device fingerprints and geolocation moreover requires a separate assessment of purpose, necessity, proportionality and GDPR legal basis. Our broader overview of analyses on AI security and fraud prevention goes into this in more depth.

What does this mean for banks now drawing up an AI risk plan?

According to ANSA of 13 September 2026, Italian banking authorities required banks to assess their AI-related cyber risks and prepare action plans, with significant banks facing an accelerated 31 October deadline. In the same report, Banca d'Italia states that incidents at Italian banks rose by 80 per cent between 2023 and 2025 and that advanced AI shortens the time between discovering and exploiting a vulnerability.

For the board this means that an AI risk plan does not stop at model security but touches the authorisation procedure itself. Concretely:

  • Record which identity claim, which channel and which human confirmation supported a sensitive payment, so that the organisation has an auditable record of the basis for the release.
  • Treat the recording of those steps as a separate layer, in line with the idea of demonstrably logging human oversight of AI decisions.
  • Test the verification chain against a simulated voice-clone attack, not only against classic phishing.

The final judgement on a suspicious order remains with the employee and the organisation. The point of this analysis is that this decision should rest on independently verified claims rather than on the credibility of a voice or a message.

Sources and references

  1. I Pm Milano indagano su altre due truffe a banche con IA, una da 24 milioniANSA · 2026-09-25
  2. Comunicazione dell'8 giugno 2026: Operatività connessa con truffe, frodi agevolate dalla tecnologia, money muling e altri reati informaticiUnità di Informazione Finanziaria per l'Italia, Banca d'Italia · 2026-06-08
  3. Avviso. Presenza in rete di falsi videomessaggi con tecniche di deepfakeBanca d'Italia · 2026-09-10
  4. Online financial frauds and scams in an artificial intelligence world: Stay alert and protect yourselfEBA, EIOPA en ESMA · 2025-12-18
  5. Ai cda banche l'esame sui rischi Ia, per le big piano azione entro ottobreANSA · 2026-09-13

Sources: The article relies on ANSA for the Milanese investigations and the banks' AI risk plan, on the UIF communication and deepfake warning from Banca d'Italia, and on the joint publication by EBA, EIOPA and ESMA.

← All articles in this topic ← All articles