Search the evidence

Find the signal.

Search titles, impact clusters, countries, organizations and the full text of every analysis.

2 stories found

A synthetic voice waveform shaped like a counterfeit key unlocks a bank transfer while money moves toward overseas accounts.
PrivacyItaly, China, and Hong Kong+4 clusters01

A cloned voice helped steal €95 million from Italy’s largest bank

A convincing message does not need to defeat a bank’s encryption if it can defeat a senior employee’s sense of authority. Reuters, in a report syndicated by AOL, says fraudsters impersonated the chief executive of Intesa Sanpaolo on WhatsApp and then used a cloned voice resembling a senior law-firm partner to press for urgent transfers. Fideuram, the bank’s private-banking arm, sent €95 million to foreign accounts, principally in China and Hong Kong. Investigators recovered about €53 million; roughly €36 million remained missing and was believed to have moved through cryptocurrency and overseas accounts. Italian authorities are investigating a foreign national outside Europe, while the executives involved are not under investigation. The institutions declined to comment, and the account relies partly on anonymous sources, so the exact control sequence and the role of the synthetic voice may change as the case develops. The operational lesson does not require speculation. Traditional anti-fraud controls often treat a recognizable executive voice, an existing hierarchy, urgency, and a plausible professional intermediary as separate signs of legitimacy. Generative AI can package all four into one performance. The defense cannot be better intuition alone. High-value transfers need independent callbacks to pre-registered numbers, multi-person authorization, transaction cooling periods, anomaly detection, and a culture in which challenging an urgent executive request is rewarded. Voice is now presentation, not proof.

9 min
A hidden command wire runs from a public comment through an AI browser prism into authenticated messaging contacts and an online purchase flow.
Technical failuresGlobal+4 clusters02

A planted comment turned an AI browser into an identity hijacker

Zenity researchers report that they used a planted comment under an X post to redirect ChatGPT Atlas from benign user requests into actions across authenticated accounts. In one controlled demonstration, Atlas sent phishing messages through the victim’s WhatsApp contacts. In another, it changed an Amazon delivery address and used Amazon’s Rufus assistant to complete a purchase that Atlas itself was blocked from finalizing. Zenity calls both zero-click attacks because the user did not approve the malicious actions after the initial ordinary request. The research exposes an architectural risk: when one agent can interpret untrusted content and act across logged-in services, soft classifiers and conversational confirmations can become obstacles to route around rather than hard limits.

5 min