Deepfake Impersonation: Voice Cloning Drains €95M From Bank

Quick answer
How do you protect yourself from a deepfake voice scam call?
Verify any urgent money request through a separate channel you already trust. Hang up and call back on a saved number, never the one that just rang. Cloning tools can copy a voice from about three seconds of audio, so listening is unreliable. A household safe word or written workplace callback rule helps.
Picture this: your boss calls, sounds exactly like your boss, and says a payment has to go out in the next hour. Deepfake impersonation is the reason you can't trust that call anymore. Your ears will tell you it's real. Your ears are now wrong often enough to matter.
Deepfake impersonation, where AI copies a real person's voice or face, has moved from party trick to bank-robbing tool, and the only dependable defense is checking urgent money requests through a second, separate channel you already know.
How Deepfake Impersonation Talked a Bank Out of Millions
Here is the case that has people talking. According to BigGo Finance, fraudsters pulled off a cyber scheme at Fideuram, the private banking arm of Italy's biggest bank. About €95 million went overseas. (The headline we tracked this week listed the figure as ₩150 billion, which looks like the same story told in Korean won. Either way, it's a huge number.)
The trick had two parts. First came WhatsApp messages pretending to be the company's chief executive. Then came a phone call with an AI-cloned voice of a lawyer. The messages built trust. The voice closed the deal. As Escudo Digital reports, about €36 million of it was then turned into cryptocurrency and hasn't been recovered.
That last detail matters more than it sounds. Once money becomes crypto and vanishes into digital wallets, getting it back is close to hopeless. The window to stop a fraud is the few minutes before the transfer.
3 seconds
of clear audio is roughly all a modern voice cloning tool needs to copy someone
Source: Polygraf AI, as summarized in our research This article is part of a series, start with Deepfake 97 Of School Victims Are Girls Most Under 15.
Why voice cloning sounds so real (deepfake impersonation by voice)
Voice cloning means software learns how one person sounds, then speaks any sentence in that voice. Deepfake technology no longer needs a Hollywood budget. It needs a short clip. And executives leave plenty of clips lying around: earnings calls, conference talks, podcasts, LinkedIn videos.
You don't have to be a chairman for this to touch you. Think about the voicemail greeting you recorded, or the birthday video you posted. That's raw material.
Is This Deepfake Financial Fraud Rare, or Is It Everywhere?
It is everywhere, and growing. Our research points to figures that should make anyone with a payment login sit up. Deepfake financial fraud attempts at contact centers (the call-in desks banks and stores run) went from roughly one a month to seven a day in 2024. Voice phishing, which is scam phone calls built to trick you into acting, jumped 442% in the second half of 2024. Another source in our notes puts CEO-style fraud at about 400 companies per day.
And 41% of chief information security officers (the people whose job is protecting a company's data) say they've already faced voice deepfake attacks. This isn't one unlucky bank. It's an assembly line.
What does the Arup case teach about deepfake financial fraud?
In January 2024, the engineering firm Arup lost the equivalent of $25.6 million. Our research describes it as the most expensive documented deepfake fraud, and here's the creepy part: every participant on the call except the victim was an AI fake. Not just a voice. A whole deepfake video meeting of people who weren't there.
So if you've been telling yourself "I'd notice if the video looked off," that's a comfortable story. It's not a plan.
Why Deepfake Impersonation Matters to Regular People
- Voice is no longer ID: "It sounded just like her" used to settle the question. It doesn't now.
- Banks are rattled too: our research says 91% of U.S. banks are reconsidering voice verification (using your voice as a security password) for major customers.
- Speed is the weapon: scammers want you panicked and quick, because thinking slowly is how fraud dies.
What Is Deepfake Impersonation, and How Is It Different From Old Scams?
Deepfake impersonation is when AI copies a real person's voice, face, or both, and uses the copy to trick someone. Old impersonation scams relied on a stranger with a good story. Now the stranger can sound like your daughter, your boss, or your bank manager. Same con, far better costume. Previously in this series: Deepfake Video Detection Fake Doctors Fool 3 In 4 People.
| Old scam call | Deepfake impersonation call |
|---|---|
| A stranger's voice, so you could rely on gut feel | A familiar voice, so your gut works against you |
| One channel, usually a phone call or email | Several channels at once, like WhatsApp messages plus a voice call |
| Needed acting skill and luck | Needs a few seconds of public audio and downloadable deepfake technology |
| Voice checks by banks were a decent safeguard | Voice checks are now an attack route |
Notice the second row. The Fideuram scheme didn't succeed on one clever trick. It layered messages and a call so each step made the next feel normal. Gartner analysis, cited in our research, describes attackers mixing phishing, hacked email, fake media, and stolen personal details. That's coordinated social engineering, not a lone prankster.
The foundational assumption that voice and video can be trusted as proof of identity is no longer safe.
CaraComp research notes on the Fideuram case
Can deepfake impersonation attacks actually be stopped?
Yes, and this is the good news. In 2024 a LastPass employee got WhatsApp voice messages in what sounded like the CEO's voice, pushing for something urgent. The attempt failed. Why? The contact came through an odd channel, outside business hours, and the employee reported it instead of acting. That's it. No fancy software. Just a pause and a "this feels wrong."
The One Habit That Beats Deepfake Impersonation
Here's my strong opinion: deepfake detection by ear is a losing game. You'll lose. Instead, change the process. Any urgent request for money, a code, or a password gets checked through a separate, known contact method. Hang up. Call back on the number you already have saved, not the one that just called you. Text a family member's other number. Walk down the hall.
For families, add a safe word (a silly phrase only your household knows, agreed in advance). For workplaces, write the callback rule down so nobody feels rude following it. Rude beats robbed.
There's a related worry too. If you've ever wondered whether a photo or profile is really the person it claims to be, that's the exact question facial comparison exists to answer: lining up two faces and measuring how alike they are. Voices can be faked from seconds of audio, so smart investigators are pairing voice checks with visual ones. A real result you can use today: before acting on a surprise request, ask for a quick live video call and watch for the person to do something you pick, like turn their head or hold up a random number of fingers. Not perfect, but it forces the scammer to work harder.
Key Takeaway Up next: Deepfake Impersonation Cloned Voice Drains 95m From Bank.
Deepfake impersonation means a familiar voice is no longer proof of who is calling, so every urgent money request needs a callback on a number you already trust.
The Fideuram victims almost certainly knew those voices and trusted those messages. So here is the question worth sitting with tonight: if the person you trust most called in a panic, what would you do in the first ten seconds, and is that the thing a scammer is counting on?
Deepfake Impersonation: Frequently Asked Questions
How can I tell if a voice on the phone is an AI clone?
Honestly, you often can't by listening. Cloning tools can copy a voice from about three seconds of clear audio, so trained ears get fooled too. Better clues are behavioral: the call is urgent, secret, or arrives on an odd channel or at an odd hour. Money, codes, or gift cards are involved. Hang up and call back using a number you already had. That one step beats nearly every voice scam.
What is deepfake financial fraud?
Deepfake financial fraud is criminal impersonation in which fraudsters use AI-made voices, faces, or video to trick people or companies into sending money or sharing account access. The reported Fideuram case, where roughly €95 million moved after a cloned voice and fake chief executive messages, is one example. Arup's loss of about $25.6 million is another. The fakes are used to build trust fast so the victim skips normal checks.
Why are banks rethinking voice verification?
Voice verification means a bank treats your voice like a password. Our research says 91% of U.S. banks are reconsidering it for major customers, because a cloned voice can now fool the very check meant to protect you. If your bank still offers it, ask what other proof it requires before large transfers, and consider adding a spoken passphrase or in-app approval instead.
How much audio does a scammer need to copy my voice?
Our research cites roughly three seconds of clear audio to build a convincing clone, with about 85% accuracy. Public clips such as conference talks, podcasts, and social videos supply plenty. You can't erase your voice from the internet, so the smarter move is to assume it can be copied and rely on a verification habit, like a family safe word and callbacks, instead of recognition.
What should a workplace do about deepfake impersonation of executives?
Write down a callback rule: any urgent payment, bank detail change, or credential reset is confirmed through a separate, known contact method, no matter who seems to be asking. Train finance and help desk staff to follow it even when the request sounds like the boss. The LastPass employee who flagged an odd WhatsApp voice message and reported it shows how well simple discipline works.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
Deepfake Video Detection: Fake Doctors Fool 3 in 4 People
Scammers are cloning real doctors' faces and voices to sell fake health products. Our eyes and ears can't catch it anymore, so here is what actually works.
privacyPlayStation Age Verification: Chat Now Costs a Face Scan
PlayStation is putting messages and voice chat behind an age check. Before your family shares a face scan or ID, here is what to ask.
ai-regulationDeepfake: One Selfie Becomes a Nude, and Sites Get 48 Hours
A selfie can be turned into a fake explicit image in minutes, and someone may see it before you know it exists. Here is what the laws cover and what to do first.
