CEO fraud: the Fideuram case, how to recall the wire transfer and document the attack
What happened at Fideuram, what your bank can still do after the wire leaves, and how to keep chats, voice notes and emails as evidence that holds up.
Updated on
CEO fraud is a scam in which criminals impersonate a senior executive, or someone acting for one, to get an employee to send an urgent, confidential payment. In the Fideuram case, made public on 25 September 2026, according to press reports a WhatsApp message, emails and a cloned voice led to wires of about 95 million euros within a few hours. After the wire, what helps is speed: a fraud recall, a police report and evidence kept in its original form.
Key takeaways
- CEO fraud is a form of business email compromise: the FBI’s IC3 logged 24,768 BEC complaints and about $3.05 billion in reported losses in 2025.
- Under the EPC SEPA Credit Transfer Rulebook, a bank can send one fraud recall per transfer up to 13 months after execution, and the beneficiary bank must answer within 15 banking business days; a refund is not guaranteed.
- A payment ordered by a deceived company is generally treated as authorized, so the PSD2 refund rules for unauthorized transactions (Directive (EU) 2015/2366) do not apply automatically.
- The original email (.eml with full headers), the chat on the receiving device and the voice notes as they arrived carry more weight than forwards or screenshots, with chain of custody along the lines of ISO/IEC 27037.
- Verification of Payee has been mandatory in the euro area since 9 October 2025 under Regulation (EU) 2024/886, but a name match does not prove the payee is legitimate.
85%
share of credit transfer fraud losses borne by payment service users in the EEA in 2024
$3.05 billion
business email compromise losses reported to the FBI in 2025
Orders from the top usually arrive with a deadline, and CEO fraud feeds on that habit. At Fideuram, part of the Intesa Sanpaolo group, the then chairman received messages that seemed to come from the group’s CEO, then a call in the voice of a well-known lawyer. The first message arrived on 23 February 2026, according to Open, and within a few hours about 95 million euros were wired abroad, as reported by Forbes Italia.
You won’t beat CEO fraud by recognizing a voice or a writing style. You beat it with a procedure: verify on an independent channel before paying; once the money has left, ask your bank for a recall, report the crime and preserve the chats, voice notes and emails.
What is CEO fraud, and how did it work at Fideuram?
CEO fraud turns an executive’s authority into a payment order, and the Fideuram case shows it now runs on chat apps and cloned voices as much as on email.
CEO fraud, also called executive impersonation or whaling, is a form of business email compromise (BEC) in which a criminal poses as a senior executive or their adviser and persuades an employee to wire money for an urgent, secret deal. The FBI’s Internet Crime Complaint Center logged 24,768 BEC complaints in 2025, with reported losses of about $3.05 billion, second only to investment fraud (FBI IC3, 2025 Internet Crime Report).
The sequence: WhatsApp, a cloned voice, payment instructions
According to press reports, Paolo Molesini, then chairman of Fideuram, received a WhatsApp message from an unknown number in the name of Carlo Messina, CEO of Intesa Sanpaolo, about an urgent operation abroad (Il Post). A call followed in the voice of Paolo Nastasi, managing partner of A&O Shearman in Italy, who had nothing to do with the scheme; the voice had been reproduced with AI tools (Forbes Italia). Emails apparently from his firm listed the accounts to pay (Il Fatto Quotidiano).
The figures, and what is still unclear
Of the roughly 95 million euros wired from Fideuram, most went to China and Hong Kong. More than 50 million euros have been blocked or seized, including over 40 million in China and over 13 million in Portugal. Between 36 and 39.5 million are still missing depending on the source: 36 million converted into cryptocurrency for Il Sole 24 Ore, 39.5 million not yet recovered for Open. According to press reports, Milan prosecutors are investigating; Molesini, who according to the reports is not under investigation, announced his resignation on 16 March 2026 “for personal reasons”.
Who CEO fraud targets
Anyone who can move money: treasury and payables staff, CFOs, executive assistants and, as Fideuram shows, people at the very top. Subsidiaries of large groups may be exposed, because an order from the parent company’s CEO sounds plausible.
CEO fraud vs BEC
BEC is the wider family of scams that abuse business communication to divert payments, and its most common form is the fake supplier invoice with a changed IBAN. CEO fraud impersonates someone higher up the hierarchy, and it is moving from email to WhatsApp and phone calls.
Why recognizing a voice or writing style is no longer enough
Every cue an employee would check can now be imitated, so the defense has to be a procedure rather than a judgment call.
Payment fraud in the European Economic Area reached 4.2 billion euros in 2024, up from 3.5 billion in 2023, and the EBA and the ECB report that manipulation of payers is growing (EBA and ECB joint report, December 2025). Strong authentication doesn’t help when the legitimate user is the one sending the money.
Urgency, secrecy, authority: the levers of the scam
Urgency removes the time to check. Secrecy (“don’t discuss this with anyone”) cuts the target off from colleagues who would ask questions, and authority makes asking feel like insubordination. The attackers used all of it: the name of the parent group’s CEO, a confidential deal abroad and a lawyer’s cloned voice on the phone.
Cloned voices and detection: a signal, not a defense
Voice cloning has turned the phone call, once the safest check, into part of the attack, as the Arup case in our analysis of voice cloning and the CFO’s defense shows. When an audio file exists, AI analysis can flag signs of a synthetic voice, but the result is probabilistic and needs a human decision. Detection is for content you have already received; certification at the source establishes what happened, as explained in deepfakes in corporate fraud and source certification and how to detect a deepfake.
Can you reverse a wire transfer after CEO fraud?
An executed wire cannot be cancelled, but your bank can send a recall, and the odds of getting money back shrink with every hour the funds have to move on.
Sometimes, partly, and only through your bank. Under the EPC SEPA Credit Transfer Rulebook, the payer’s bank can send a recall for a fraudulent transfer up to 13 months after execution, and the beneficiary bank must answer within 15 banking business days. Nothing guarantees a refund: money comes back only if it is still in the account or frozen by authorities.
| Action | When | Who |
|---|---|---|
| Ask your bank for a fraud recall | As soon as you suspect the scam | Whoever ordered the payment |
| Recall sent to the beneficiary bank | Up to 13 months after execution (SEPA) | Your bank |
| Answer from the beneficiary bank | Within 15 banking business days (SEPA) | Beneficiary bank |
| Police report | The same day | Legal or management |
| Preserve chats, emails and devices | Before anything is deleted or forwarded | Recipients of the messages, with IT |
What the SEPA recall rules say
A bank can send only one recall per transfer. No reply in time counts as a negative answer, and the amount returned may be lower than the amount sent. The rulebook doesn’t say whether a payment your own staff ordered under deception counts as “fraudulently originated”, so ask your bank which route it is using.
Instant and cross-border transfers
An instant transfer lands within seconds and can’t be revoked after execution, so only a recall is left. Wires leaving the SEPA area, like most of the Fideuram transfers, fall outside the EPC rules: requests go through correspondent banks, and freezes by local authorities often matter more.
Authorized or unauthorized payment
When the order comes from the company itself, even if deceived, the payment is generally treated as authorized, which means the refund rules for unauthorized transactions under the PSD2 Directive (EU) 2015/2366 do not apply automatically, and the bank’s share of responsibility is assessed case by case. According to the EBA and ECB, users bore about 85% of credit transfer fraud losses in 2024, mainly from scams that tricked them into initiating payments.
-
Call your bank and ask for a fraud recall
Give the date, amount, beneficiary IBAN and reference, say it is a recall for fraud, and confirm in writing the same day.
-
File a police report
Report to the police or your national cybercrime unit (in the United States, IC3); investigators can request freezes abroad. See how to report an online scam.
-
Lock down the channels and preserve the devices
Block the attackers’ numbers and addresses, reset exposed credentials, and make sure nobody deletes or “cleans up” the chats on the devices that received them.
-
Notify your insurer and counterparties
Crime and cyber policies set notice deadlines. Warn any partner whose name the attackers used, too.
What evidence should you keep after CEO fraud, and how do you make it hold up?
Evidence holds up when it stays in its original form with a documented chain of custody; forwards and screenshots keep the words but lose the proof of where they came from.
You need the original email as an .eml file with full headers, the chat on the device that received it, and the voice notes as they arrived. For the call, note number, time and duration from the call log: a live call leaves no file unless someone recorded it.
Email, chat and voice notes: what you need from each
Email headers show the route between servers and the SPF, DKIM and DMARC results, which reveal whether the sender’s domain was spoofed. With TrueScreen, whoever received the fake executive’s email can certify it in its original format, with every header and those three results, so the bank and investigators can see which server it came from. A chat needs the sender’s number, dates, times and the thread around the payment instructions, because WhatsApp chats as evidence are judged in context. Voice notes should stay in the original conversation, linked to sender and time, as explained in voice notes as court evidence.
Why forwards and screenshots carry less weight
A forwarded email is a new message with new headers, so the original route is gone. A screenshot is a set of pixels, easy to edit and silent about its source, and a forwarded voice note becomes a message from whoever forwarded it. Weight comes from the chain of custody (who collected each item, when, how, and proof it hasn’t changed since), along the lines of ISO/IEC 27037 on handling digital evidence.
The internal procedure for urgent and confidential payment requests
A payment request that invokes urgency and secrecy should trigger more checks, not fewer, even when it appears to come from the top.
The controls that work are organizational and cheap; write them down and make clear that no executive can waive them.
-
Call back on a channel you already hold
Check any unusual request by calling the executive on a number from your internal directory, never one supplied in the message.
-
Require a second approver
Above a set threshold, new beneficiaries and urgent transfers need sign-off from a second person who did not receive the request.
-
Read the Verification of Payee result
Under the Instant Payments Regulation (EU) 2024/886, Verification of Payee has been mandatory in the euro area since 9 October 2025: before you authorize a transfer, your bank checks free of charge whether the beneficiary’s name matches the IBAN (ECB, instant payments). A mismatch should stop the payment. A match only confirms that the account belongs to that name, not that the payee is legitimate, and accounts outside the EU get no such check.
What can TrueScreen prove after a CEO fraud attack?
TrueScreen certifies what arrived, from whom and when; it does not certify that the content is true, and that is what you need to show you were deceived.
TrueScreen, the Data Authenticity Platform, certifies at the source what you acquire with forensic methodology: chats, WhatsApp Web, original emails and saved files. Every certification carries a qualified electronic seal and a qualified timestamp, and the method preserves the chain of custody in line with ISO/IEC 27037. The court assesses the weight of the evidence case by case.
Chats on the phone: certified screen recording
In the TrueScreen App you record the screen while scrolling through the conversation; the certification covers what appears and plays on screen, including contact details, voice notes and photos. More on certified WhatsApp chats.
WhatsApp Web and detection: the Forensic Browser
On a computer, the Forensic Browser acquires WhatsApp Web, including network traffic and attachments. It also runs AI analysis on photos, video and audio: detection is an additional signal, while certification at the source establishes what happened.
Emails: Mail Certification
Mail Certification works with any mail client: you add your workspace’s dedicated address in To, Cc or Bcc, or set a forwarding rule. It certifies the original .eml and each attachment (except calendar invitations) with a SHA-256 fingerprint; the report shows dates, sender, recipients, SPF, DKIM and DMARC results and all original headers. See how to certify an email.
Files already exported
A chat export or a saved voice note can be certified as a file. Certifying the export proves the file hasn’t changed from that moment on; it is not a forensic acquisition and doesn’t prove when the messages were sent. To certify the conversation itself, record it with the TrueScreen App.
Picture treasury realizing on Monday that Friday’s urgent transfer was a scam: one person calls the bank for the recall while the colleague who received the messages certifies the chat and the original email, so the police report rests on more than screenshots.
Conclusion
The Fideuram case shows how little a familiar name, tone or voice proves on its own. Before the payment, the defense is organizational: a call-back on a channel you already hold, a second approver and a careful look at the Verification of Payee result. After it, the order of moves matters: the recall request to your bank, the police report and evidence kept in its original form. A recall is never guaranteed, but chats, voice notes and emails acquired at the source give your bank, investigators and insurer something solid to work with.
FAQ: common questions about CEO fraud
What is the difference between CEO fraud and BEC?
Business email compromise (BEC) covers scams that abuse business communication to divert payments, such as fake supplier invoices. CEO fraud is the variant in which the criminal impersonates a senior executive or their adviser. The FBI’s IC3 recorded 24,768 BEC complaints and about $3.05 billion in reported losses in 2025.
Can a wire transfer be reversed after CEO fraud?
An executed wire can’t be cancelled, but your bank can send a recall. Under the EPC SEPA Credit Transfer Rulebook, a fraud recall can be sent once, up to 13 months after execution, and the beneficiary bank must answer within 15 banking business days. Money returns only if it is still there or frozen and, in many cases, with the beneficiary’s consent.
Are instant payments irrevocable?
From the payer’s side, yes: an instant credit transfer lands within seconds and can’t be revoked. Your bank can still request a recall, which works only if the funds are still in the account. Since 9 October 2025, euro-area banks must offer Verification of Payee before you authorize a transfer.
How do you get your money back after CEO fraud?
Ask your bank for a fraud recall at once, then file a police report so investigators can request freezes abroad. Under PSD2, a payment ordered by a deceived company is generally treated as authorized, so a refund is not automatic. In the Fideuram case, more than 50 of about 95 million euros were blocked or seized.
Who is targeted by CEO fraud?
Anyone who can move money: treasury and payables staff, CFOs, executive assistants and board members. In the Fideuram case, made public in September 2026, the target was the bank’s then chairman, and about 95 million euros were wired within a few hours.
Sources and verification
Every figure and principle cited here links to its source, listed with type and date. Links checked on the publication date.
| Source | Type | Date | What it supports |
|---|---|---|---|
| Il Sole 24 Ore, The former boss of Fideuram was scammed via WhatsApp and 36 million have gone missing | Survey | 25/09/2026 | Fideuram case: amounts, dates and missing funds |
| Il Post, Fideuram scam via WhatsApp and AI | Survey | 25/09/2026 | WhatsApp message in the name of Carlo Messina |
| Forbes Italia, Fideuram scam: 95 million via WhatsApp and AI | Survey | 25/09/2026 | Cloned voice of the lawyer and wires within a few hours |
| Il Fatto Quotidiano, CEO fraud at Fideuram: 95 million | Survey | 25/09/2026 | Emails with the accounts to pay |
| Open, Molesini and Fideuram scam: suspect under investigation | Survey | 25/09/2026 | Date of the first message and 39.5 million not yet recovered |
| FBI IC3, 2025 Internet Crime Report | Survey | 2026 | BEC complaints and reported losses in 2025 |
| EBA and ECB, joint report on payment fraud (press release) | Survey | 15/12/2025 | EEA fraud losses in 2024 and share borne by users on credit transfers |
| EPC, SEPA Credit Transfer Rulebook 2025 version 1.0 (EPC125-05) | Document | 28/11/2024 | Recall for fraud: 13 months, 15 banking business days, one recall per transfer |
| Directive (EU) 2015/2366 (PSD2) | Law | 25/11/2015 | Authorized and unauthorized payment transactions |
| Regulation (EU) 2024/886 (Instant Payments Regulation) | Law | 13/03/2024 | Mandatory Verification of Payee in the euro area |
| ECB, Instant payments | Document | 2025 | Instant payments and Verification of Payee |
Evidence of an attack that holds up
Certify chats, emails with their original headers and web pages at the source, with a qualified electronic seal and a qualified timestamp on every certification. Request a demo to see how it works for your finance team.
TrueScreen editorial team
This section is edited by the TrueScreen editorial team, which brings together expertise in digital forensics, the law of digital evidence and regulatory compliance. Every article is checked against primary sources: legislation, published rulings, technical standards and official documentation, always cited in the text.
