{
 "date": "2026-09-29",
 "issue": 4,
 "status": "published",
 "incidents": [
  "RL-I-2026-0001",
  "RL-I-2026-0046",
  "RL-I-2026-0175",
  "RL-I-2026-0177"
 ],
 "removed": 7,
 "examined": 31,
 "windowUntil": "2026-09-29 20:06:25",
 "summary": [
  "Cybercriminals reportedly used AI voice cloning and deceptive messaging to steal 95 million euros from the Italian bank Fideuram [1, 2, 3]. The attackers impersonated a CEO and a lawyer to authorize fraudulent overseas transfers [1, 2, 3]."
 ],
 "main": {
  "headline": "AI voice cloning and deceptive messaging facilitate 95 million euro bank heist",
  "paragraphs": [
   "Cybercriminals reportedly used AI and fake messages to impersonate senior executives and a lawyer to steal 95 million euros from the Italian private bank Fideuram [1]. The attack reportedly began in February 2026 when the bank's then president, Paolo Molesini, received a WhatsApp message appearing to be from the CEO of the parent company, Intesa Sanpaolo [1, 2, 3]. The message requested urgent help with an international transaction [1, 2, 3].",
   "Following the message, Molesini reportedly received a phone call from someone posing as a senior partner at an Italian law firm to confirm the transaction [1, 2]. Sources told Reuters that the caller's voice was a replica made with AI [2]. A spoofed email from the law firm reportedly provided the necessary bank account details [2].",
   "Fideuram later detected irregularities and alerted authorities [1, 2]. Cooperation between officials in China, Portugal, and Italy reportedly allowed for the recovery of approximately 53 to 60 million euros [2, 3]. About 36 to 40 million euros reportedly remain missing after being converted into cryptocurrencies [2, 3]."
  ]
 },
 "supplementals": [
  {
   "headline": "North Korean IT cell uses female personas for employment fraud",
   "paragraphs": [
    "A researcher claims a North Korean IT cell is using women with limited technical knowledge to pose as software developers to trick Western companies into hiring them [4]. These women reportedly act as the face of the candidates during interviews and meetings, while developers provide technical support off-screen [4].",
    "The cell reportedly builds profiles using stolen data, ChatGPT prompts, and transcripts from the sitcom Friends to assist with conversational English [4]. One workbook reportedly contained approximately 1,200 female personas [4]. The US firm MageHire is alleged to be a front company for these operations [4]."
   ]
  },
  {
   "headline": "Carbonato Botnet deploys AI agent on Docker hosts",
   "paragraphs": [
    "The Carbonato Botnet reportedly uses the open source Hermes Agent AI framework to execute commands via Telegram [5]. The botnet reportedly targets exposed Docker hosts [5]. Once a host is compromised, the agent reportedly attempts to steal AI API keys [5]."
   ]
  },
  {
   "headline": "AI agent performs messy autonomous breach of DIVD",
   "paragraphs": [
    "DIVD described the attack as loud, messy, and agentic in nature [6].",
    "The organization reported that the agent worked autonomously, deciding its own next steps at high speed [6]. Researchers at DIVD claimed the agent performed poorly trained actions, such as interfering with its own adversary-in-the-middle attack via password spraying [6]. The agent reportedly over-explained its decisions in its comments [6]."
   ]
  }
 ],
 "references": [
  {
   "n": 1,
   "source": "escudodigital.com",
   "title": "Voice deepfake heist: €95 million stolen from Italian bank | DigitalShield",
   "url": "https://escudodigital.com/en/cybersecurity/voice-deepfake-heist-95-million-stolen-from-italian-bank.html",
   "published": "2026-09-29",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0001",
   "archiveUrl": "https://web.archive.org/web/20260929134222/https://escudodigital.com/en/cybersecurity/voice-deepfake-heist-95-million-stolen-from-italian-bank.html"
  },
  {
   "n": 2,
   "source": "uncovai.com",
   "title": "AI Voice Cloning Fraud: How €95M Left an Italian Bank - UncovAI",
   "url": "https://uncovai.com/ai-voice-cloning-fraud-intesa-sanpaolo",
   "published": "2026-09-28",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0001",
   "archiveUrl": "https://web.archive.org/web/20260928213708/https://uncovai.com/ai-voice-cloning-fraud-intesa-sanpaolo"
  },
  {
   "n": 3,
   "source": "www.techradar.com",
   "title": "Italy's top bank hit by an AI messaging scam which cost it nearly €100 million",
   "url": "https://www.techradar.com/pro/security/italys-top-bank-hit-by-an-ai-messaging-scam-which-cost-it-nearly-eur100-million",
   "published": "2026-09-29",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0001",
   "archiveUrl": "https://web.archive.org/web/20260929154332/https://www.techradar.com/pro/security/italys-top-bank-hit-by-an-ai-messaging-scam-which-cost-it-nearly-eur100-million"
  },
  {
   "n": 4,
   "source": "cybernews.com",
   "title": "North Korea fake IT workers use women, Friends and ChatGPT | Cybernews",
   "url": "https://cybernews.com/security/north-korea-female-fake-it-workers-friends/",
   "published": "2026-09-29",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0177",
   "archiveUrl": null
  },
  {
   "n": 5,
   "source": "darkreading",
   "title": "Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts",
   "url": "https://www.darkreading.com/identity-access-management-security/carbonato-botnet-ai-agent-hacked-docker-hosts",
   "published": "2026-09-28",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0046",
   "archiveUrl": null
  },
  {
   "n": 6,
   "source": "bleepingcomputer",
   "title": "Automated AI agent used to breach cybersecurity nonprofit DIVD",
   "url": "https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/",
   "published": "2026-09-29",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0175",
   "archiveUrl": "https://web.archive.org/web/20260929160559/https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/"
  }
 ]
}
