AI Voice Scam Triggered €95M, Plus 4 Stories
An AI voice scam does not have to fool a bank’s security software. It only has to fool the person who is allowed to tell the bank’s finance department to move the money.
That is the uncomfortable part of a €95 million fraud at Fideuram, the private-banking arm of Italy’s Intesa Sanpaolo. The attack combined old-fashioned impersonation with a much newer trick: a cloned voice that made an extraordinary request sound like it had been independently confirmed.
An AI-cloned voice helped confirm a €95 million payment request
Reuters reports that the scheme began in February when Paolo Molesini, then chairman of Fideuram, received what appeared to be a WhatsApp message from Intesa Sanpaolo CEO Carlo Messina asking for urgent help with an overseas transaction. The attackers then followed up with a phone call that appeared to come from a senior partner at a law firm Molesini knew.
That second contact is where the AI matters. According to Reuters’ sources and the original reporting by Corriere della Sera, the callers replicated the lawyer’s voice with AI. Emails that appeared to come from the law firm supplied the foreign beneficiary accounts. Molesini believed the request was legitimate and instructed Fideuram’s finance department to make a series of transfers, mostly to accounts in China and Hong Kong.
Fideuram caught the irregularities quickly enough to recover roughly €53 million through banks and authorities in China, Portugal and Italy. About €36 million remains missing after money moved through overseas accounts and was converted into cryptocurrency, Reuters says. Intesa Sanpaolo and Fideuram declined to comment, and Reuters’ sources said Molesini and other Fideuram executives are not under investigation.
There is a useful correction here to security advice I have given for years. “Pick up the phone and verify” is no longer sufficient by itself. If the attacker supplied the number, initiated the call or is already impersonating somebody you know, the second channel can simply be another part of the same attack.
For businesses, the safer version is: verify an unusual payment request through a contact method you already trust, not one that arrived with the request. Call a known number from your directory or previous records. Require a second human approval for unusual transfers. And do not treat a familiar voice as authentication. Voice is now evidence that somebody sounds familiar. That is not the same thing.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
Two Citrix NetScaler flaws are already being exploited
If you run Citrix NetScaler ADC or NetScaler Gateway, this one moves directly into the “do something” pile.
Citrix disclosed two critical vulnerabilities Sunday and says both have been exploited on unmitigated customer-managed systems. CVE-2026-88771 is an improper-input-validation flaw that can let an unauthenticated attacker execute arbitrary commands. It affects vulnerable NetScaler ADC and Gateway deployments without requiring a particular optional feature.
CVE-2026-88772 is a memory-overflow flaw that can lead to remote code execution or denial of service when DTLS is enabled. That sounds like a narrower condition until you get to the important part: Citrix says DTLS is enabled by default on VPN virtual servers.
The fixed mainstream builds are 14.1-73.37 or later and 13.1-64.23 or later, with separate fixed builds for FIPS and NDcPP branches. Citrix-managed cloud services were updated by Citrix; customer-managed appliances and hybrid deployments using customer-managed NetScaler instances need attention from the operator.
CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog. BleepingComputer reports that federal agencies have until September 30 to secure affected systems, and CISA recommends preserving useful forensic evidence and checking for compromise before updating when that is practical.
That last part matters because patching answers one question: “Is the hole still open?” It does not answer another: “Did somebody already come through it?” Internet-facing VPN and gateway appliances are exactly the sort of systems where I would want both answers.
Nvidia is building walls around AI agents instead of asking them to behave
Yesterday’s Weekly Digest spent a lot of time on a simple idea: instructions are not access controls. Nvidia is now shipping a fairly literal engineering version of that principle.
The company released agent-safety tooling around OpenShell, which puts an AI agent inside a sandbox and controls what it can reach. Nvidia’s own documentation describes deny-by-default controls across the network, filesystem, processes, gateway authentication and model-inference layer. An operator can decide which hosts, ports and HTTP methods the agent may use, and the system can keep credentials outside the agent’s direct reach.
Reuters also describes a companion system called Sentry that uses a separate Nvidia chip with OpenShell and can cut off an agent that appears to be escaping its container. Nvidia says the tooling can detect workaround behavior such as an agent spawning multiple sub-agents to try to get around a restriction.
Nvidia vice president Justin Boitano says the platform could have stopped the recent Hugging Face incident. That is Nvidia’s counterfactual claim about its own product, not something we can go back and prove. The architecture is the more interesting part anyway.
If you are experimenting with agents inside a business, you do not need Nvidia hardware to adopt the principle. Give the agent a dedicated account. Give that account only the permissions it needs. Isolate the environment where you can. Restrict outbound network access. Keep production credentials away from a tool that does not need them. The goal is not to write a better sentence telling the model where the boundary is. The goal is to make the boundary real.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Apple and Amazon still have to answer one UK marketplace claim
A UK consumer lawsuit accusing Apple and Amazon of restricting competition in the sale of Apple products has been narrowed, not thrown out.
Britain’s Competition Appeal Tribunal ruled Monday that a claim involving Apple’s 2018 agreement with Amazon can proceed. The allegation is that restrictions on which resellers could sell Apple and Beats products through Amazon’s UK marketplace reduced competition and raised prices. Reuters reports that the surviving marketplace portion is valued by the claimant at roughly £289 million to £306 million including interest.
The tribunal rejected the broader theory that the agreement also pushed up prices at other retailers. And this certification decision is not a finding that Apple or Amazon broke competition law. It means the narrower marketplace claim is plausible enough to be litigated.
For small sellers, the reason to watch is bigger than Apple. Marketplace access rules are not just housekeeping inside somebody else’s website. When a platform and a major manufacturer decide who is allowed to sell what, those rules can influence both seller access and the prices customers actually see.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Edge computing is going to space — literally
And finally, Indian startup TakeMe2Space plans to launch a satellite on SpaceX’s Transporter-18 mission October 1 that will process customer data in orbit instead of sending all of the raw information back to Earth first.
The satellite, called MOI-1A, weighs less than 50 kilograms and carries Nvidia Orin NX processors. Reuters reports that TakeMe2Space has signed 23 customers and expects uses in agriculture, mining, supply chains, insurance, mapping and education. Customers can upload containerized AI models; the satellite can run those models against imagery or other data and transmit the result instead of the entire dataset.
This is not a data center floating over your house. The satellite has roughly 150 watts of power, and TakeMe2Space’s first MOI-1 mission was lost when its launch vehicle suffered a third-stage failure. The company says larger networked satellites are planned for 2027.
Still, the underlying idea makes sense. Moving raw satellite data to Earth can be slow and expensive when the customer only needs an answer such as “which fields show crop stress?” or “where did this terrain change?” Do some of the computing where the data is created and send down the smaller result.
It is edge computing. The edge just happens to be in orbit.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters — AI messaging scam costs Italy’s top bank Intesa millions
- Corriere della Sera — Fideuram fraud and the AI-cloned voice call
- Citrix — NetScaler security bulletin CTX697096
- BleepingComputer — CISA orders agencies to secure exploited Citrix flaws
- Reuters — Nvidia releases AI agent safety software
- Nvidia — NemoClaw security controls and best practices
- Reuters — Apple and Amazon face revived UK consumer lawsuit
- Reuters — TakeMe2Space plans orbital computing satellite
Photo by David Hahn on Unsplash.
