← The Red Lens: every edition

29 September 2026 · Issue 4

AI voice cloning and deceptive messaging facilitate 95 million euro bank heist

Markdown · JSON · RSS · For agents

Each reference carries its source's own evidence class. A story is never summarised by its strongest source.

Summary

Cybercriminals reportedly used AI voice cloning and deceptive messaging to steal 95 million euros from the Italian bank Fideuram [1, 2, 3]. The attackers impersonated a CEO and a lawyer to authorize fraudulent overseas transfers [1, 2, 3].

Main story: AI voice cloning and deceptive messaging facilitate 95 million euro bank heist

Cybercriminals reportedly used AI and fake messages to impersonate senior executives and a lawyer to steal 95 million euros from the Italian private bank Fideuram [1]. The attack reportedly began in February 2026 when the bank's then president, Paolo Molesini, received a WhatsApp message appearing to be from the CEO of the parent company, Intesa Sanpaolo [1, 2, 3]. The message requested urgent help with an international transaction [1, 2, 3].

Following the message, Molesini reportedly received a phone call from someone posing as a senior partner at an Italian law firm to confirm the transaction [1, 2]. Sources told Reuters that the caller's voice was a replica made with AI [2]. A spoofed email from the law firm reportedly provided the necessary bank account details [2].

Fideuram later detected irregularities and alerted authorities [1, 2]. Cooperation between officials in China, Portugal, and Italy reportedly allowed for the recovery of approximately 53 to 60 million euros [2, 3]. About 36 to 40 million euros reportedly remain missing after being converted into cryptocurrencies [2, 3].

Supplemental

North Korean IT cell uses female personas for employment fraud

A researcher claims a North Korean IT cell is using women with limited technical knowledge to pose as software developers to trick Western companies into hiring them [4]. These women reportedly act as the face of the candidates during interviews and meetings, while developers provide technical support off-screen [4].

The cell reportedly builds profiles using stolen data, ChatGPT prompts, and transcripts from the sitcom Friends to assist with conversational English [4]. One workbook reportedly contained approximately 1,200 female personas [4]. The US firm MageHire is alleged to be a front company for these operations [4].

Carbonato Botnet deploys AI agent on Docker hosts

The Carbonato Botnet reportedly uses the open source Hermes Agent AI framework to execute commands via Telegram [5]. The botnet reportedly targets exposed Docker hosts [5]. Once a host is compromised, the agent reportedly attempts to steal AI API keys [5].

AI agent performs messy autonomous breach of DIVD

DIVD described the attack as loud, messy, and agentic in nature [6].

The organization reported that the agent worked autonomously, deciding its own next steps at high speed [6]. Researchers at DIVD claimed the agent performed poorly trained actions, such as interfering with its own adversary-in-the-middle attack via password spraying [6]. The agent reportedly over-explained its decisions in its comments [6].

References

  1. Voice deepfake heist: €95 million stolen from Italian bank | DigitalShield · escudodigital.com · threat intel report · 2026-09-29 · RL-I-2026-0001
  2. AI Voice Cloning Fraud: How €95M Left an Italian Bank - UncovAI · uncovai.com · threat intel report · 2026-09-28 · RL-I-2026-0001
  3. Italy's top bank hit by an AI messaging scam which cost it nearly €100 million · www.techradar.com · threat intel report · 2026-09-29 · RL-I-2026-0001
  4. North Korea fake IT workers use women, Friends and ChatGPT | Cybernews · cybernews.com · threat intel report · 2026-09-29 · RL-I-2026-0177
  5. Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts · darkreading · threat intel report · 2026-09-28 · RL-I-2026-0046
  6. Automated AI agent used to breach cybersecurity nonprofit DIVD · bleepingcomputer · threat intel report · 2026-09-29 · RL-I-2026-0175