Stealing 100 million with a Whatsapp: what you don’t know about the Fideuram bank scam

A message, then other contacts on WhatsApp and a series of bank transfers: within a few days, millions of euros end up in foreign accounts. This time, however, the victims are not elderly people or …

Stealing 100 million with a Whatsapp: what you don't know about the Fideuram bank scam

A message, then other contacts on WhatsApp and a series of bank transfers: within a few days, millions of euros end up in foreign accounts. This time, however, the victims are not elderly people or simple unprepared savers, but the top management of a bank. The scam involving Paolo Molesini, president of Fideuram up to that point, is a true summary of the dangers that anyone can run into when social engineering techniques meet new technologies. A risk that concerns everyone today. The defrauded bank and its parent company immediately activated protective measures as soon as the scam was discovered. So much so that part of the money has already been recovered. But the poor president had to resign. But here are the details of the operation, which we did not know.

The scam against Fideuram from the beginning

The scam against Fideuram, according to the reconstruction contained in a seizure decree of the Court of Milan, began on 23 February 2026. President Paolo Molesini receives a WhatsApp message from a man who introduces himself as Carlo Messina, CEO of Intesa Sanpaolo. A premise: Fideuram is part of the Intesa Sanpaolo group and is its branch dedicated to private banking and financial consultancy.

The new trick that empties your bank account in a few minutes: how to recognize the perfect mobile phone scam – by Daniele Tempera

However, there is one aspect that does not go unnoticed: the number from which the alleged Messina writes is different from the one Molesini knows. What convinces him are the familiar tone and the references used by the sender. The false Messina tells him about the urgent acquisition of an international bank: the operation, he claims, must remain secret and pass through Fideuram to avoid a leak of information blowing it up. This creates a psychological pressure of haste and maximum confidentiality: recurring elements in scams based on social engineering.

The former president of Fideuram bank Paolo Molesini (Youtube photo)

A bank, however, is not a private individual and personal persuasion is not enough. Other elements are needed to give credibility to the request and start the payments. Elements that arrive punctually like the hands of a clock. Molesini is contacted by a man who introduces himself as the lawyer Paolo Nastasi of the A&O Shearman firm. The lawyer really exists and is associated with the firm. But the person contacting the president is an impostor who uses his name. The self-styled lawyer asks to sign a confidentiality agreement and sends a power of attorney apparently signed by the top management of Intesa Sanpaolo, followed by eleven payment instructions on the firm’s headed paper. For Molesini, the documents strengthen the credibility of the operation.

The decisive confirmation, however, comes from another move, which involves a third person: Dario Tramarin, head of finance and treasury at Fideuram. He too receives a WhatsApp message, this time from someone pretending to be the CEO of the company. The false Ad tells him that Molesini will contact him to arrange urgent and confidential transfers. When the request actually comes from the president, Tramarin then finds apparent confirmation. The mechanism, at that point, is complete and the transfers are ready to go. But it’s important to keep an eye on the calendar.

The 48-year-old under investigation and the time factor

The first transfer starts on February 23, 2026: 4.98 million euros to an account of the Portuguese company “Vertentarticulada” at Banco BPI. On February 24th another six transfers followed, made out to other Portuguese companies.

Finally, on February 25, four payments totaling 42.565 million euros were made to the “Goldspring” company, into an account at the Bank of China in Hong Kong. According to the decree, the eleven transfers reach a total of 95.18 million euros. And the timing is not a detail: the first money leaves on February 23, the same day that Molesini receives the message from the fake Messina. The transfers continue over the next two days.

Time is a fundamental ingredient of the scam. On February 25, just two days after the first contact, Banco BPI reported to Fideuram the suspicious nature of the transactions. Internal checks bring down the fraudsters’ house of cards, but part of the money has already been moved.

Our identity cards on sale for less than a coffee: but they can cost us our bank account – by Daniele Tempera

The bank manages to get the 42.565 million euros sent to Hong Kong returned, while 13.1 million remaining with Banco BPI are administratively blocked. However, around 39.5 million euros are missing from the appeal. According to investigators, the unstopped money quickly passes through foreign accounts and payment operators, up to platforms that deal in cryptocurrencies: a path that complicates its recovery.

The only suspect identified in the decree is a 48-year-old Israeli citizen. The investigators arrived at his name by following the flows of money converted into cryptocurrencies: at least 4,260 dollars would have ended up in his availability and then credited to an online casino account “Stake.com” in his name. It is a small amount compared to the missing money. It remains to be ascertained whether the man actually controlled that account and, above all, what role he had in the scam.

conviction_american_department_of_justice
The news on the US Department of Justice website

However, there is a striking precedent. The same name appears in the archives of the US Department of Justice, associated with a fraud with a very similar mechanism. Arrested in Israel and extradited to the United States, the fraudster pleaded guilty and was sentenced to 43 months in prison in 2018 for participating in a ring posing as business executives. The accomplices persuaded employees to arrange wire transfers for supposedly confidential financial transactions, including “secret” corporate takeovers. Once received, the money was quickly transferred to other accounts, out of reach of the victim companies. According to the Department of Justice, the scheme brought in over a million dollars.

The similarity with the Fideuram case is evident, but the American precedent is obviously not proof and the magistrates hypothesize the contribution of other people, currently unknown.

Spoofing and phishing: the probable ingredients of the scam

Yes, because the first thing to do is to free ourselves from the idea of ​​the hacker as an individual who acts alone. Cybercrime is now made up of organized networks, in which skills, data and tools can be exchanged or sold. Some of these markets are located on the dark web, a part of the Internet accessible through specific software, such as Tor, designed to make it more difficult to identify users. A scam like the one against Fideuram can be seen as a puzzle, in which information about people, false identities and documents that appear credible come into play.

The scammers knew who to involve and how to reach them. They even had the personal number, normally reserved, of the Fideuram treasury manager. Before the attack they may have collected information from public sources, from hacked accounts or from data stolen in previous data breaches. Or they could even have purchased contact details from other criminals. These are concrete possibilities, even if not yet expressly evoked by the investigations.

SPOOFING_wikimedia
How spoofing works

Then comes the first conversation via WhatsApp between the fake Messina and Molesini. The president also trusts the colloquial tone and references used by the sender, even though the number is different from the one he knows. How they learned to reproduce that familiarity is another open question. They may have studied relationships between managers or had access to previous communications, including through the possible installation of spyware, although the investigation will have to establish how, if any. Certainly, the story of the confidential acquisition was constructed to appear credible to Molesini.

Then there is the impersonation: the scammers pass themselves off as the CEO of Intesa Sanpaolo, that of Fideuram and as a real existing lawyer. In the case of the first phone call we know that Molesini noticed the difference between the false Messina address and the one he knew. However, we have no details on the exchange between the Fideuram treasurer and the fake CEO who set the scam in motion.

I lost 500 euros in a few minutes with spoofing: the three rules to avoid the perfect scam – by Daniele Tempera

As for the self-styled lawyer Nastasi, the investigators ascertained that the number with a British prefix used to contact Molesini had been activated via the Internet, via one of the many online software designed for this function, and was therefore not connected to a real person. The principles in this case are the same as the so-called “spoofing”, the technique that can make a number appear on the victim’s phone that is different from the one actually used, using a simple VoIP account, even if at the moment no real technical manipulation of the telephone number has been ascertained.

Investigators also discovered that the scammers had created an email account on Mailbox.org in the name of Paolo Molesini. According to the provision, the mailbox was provided to the president by the fake lawyer, was controlled by the scammers and was used for primary communications and document exchange. Messages and files would then be deleted from there. To complete the charade, a power of attorney apparently signed by the top management of Intesa Sanpaolo and payment instructions on the law firm’s headed paper, with the apparent signature of another lawyer.

The function of voice cloning and cryptocurrencies

Finally, there is a technique that could have contributed to the scam, but for which the documents do not yet offer an answer: the possible imitation of the voice. According to some journalistic reconstructions, Molesini would have recognized that of the lawyer Nastasi and also for this reason he would have trusted his interlocutor. If the detail were confirmed, it would remain to be understood how that effect was achieved. One possibility is voice cloning, that is, the artificial reproduction of a person’s voice starting from his recordings. A hypothesis that shows how much a voice, today, can become an instrument in the hands of scammers: a voice message or a public intervention can provide material to try to imitate its timbre and cadence, as we have explained in this in-depth analysis.

cryptocurrency_soldi_fideuram
Where does the money go in the scam against Fideuram?

Once the transfers have been made, the money path also comes into play. According to investigators, the approximately 39.5 million euros not stopped in Portuguese accounts are quickly moved through foreign accounts and payment operators, passing through Malta, Luxembourg and the Netherlands, among others, to a Canadian platform and cryptocurrency wallets.

“Minister Piantedosi’s email has been hacked”, the Ministry of the Interior has been informed for 5 months: but no one stopped the hackers from attacking Banca Revolut – by Fabrizio Gatti

Transfers between multiple intermediaries make it difficult to block the funds in time and reconstruct who had access to them. However, cryptocurrencies do not erase the traces: it was precisely by following those movements that the investigators identified a small sum attributed to the suspect and subsequently credited to an online casino account. In short, the scenario is that of a plan orchestrated down to the smallest detail carried out with the help of multiple techniques which, every day, are used more and more often to defraud even ordinary citizens.

Dossier is the exclusive subscription investigative section of The Vermilion. If you want to support our journalistic work and subscribe, Click here.

Read the other The Vermilion Dossiers