Voice-Cloned Defence Minister Convinced Italy's Business Elite to Wire Millions
What happened
In February 2025, a group of prominent Italian entrepreneurs received urgent phone calls that appeared to come from official government lines. The caller identified himself as Defence Minister Guido Crosetto or a member of his staff, requesting funds to secure the release of Italian journalists allegedly held hostage in the Middle East. The voice was convincing because it was not an impersonator working from memory. Scammers had used AI voice-cloning technology to replicate Crosetto's voice and spoofed government phone numbers to make the origin of each call appear legitimate.
The timing was deliberate. Weeks earlier, Italian journalist Cecilia Sala had been detained in Iran and released in a widely covered diplomatic sequence. That real event gave the fabricated hostage scenario a ready-made frame. Anyone following the news would have found the premise plausible, and the businessmen being targeted were precisely the kind of people who do follow such events closely. A cloned ministerial voice, calls appearing to originate from official numbers, and a pretext drawn from recent headlines combined into a tightly layered deception.
The scheme drew in some of Italy's most prominent figures. Among those contacted were fashion designer Giorgio Armani, former Inter Milan owner Massimo Moratti, Patrizio Bertelli, and members of the Beretta and Menarini families. At least one transfer was completed: Moratti wired approximately one million euros to a Hong Kong bank account, having been told the Bank of Italy would reimburse him once the journalists were safely home. Authorities recovered the funds, but the fact that a transfer of that size was completed at all showed how thoroughly the fraud had worked.
The attack succeeded because each layer of deception reinforced the others. Voice cloning made the caller sound right. Number spoofing made the origin look right. A plausible, news-grounded pretext made the request feel urgent. Any one element alone would have been easier to dismiss. Together, they constructed a synthetic trust environment designed to suppress skepticism before it could engage, working fastest on people who had the most reason to believe a defence minister might call them directly.
What this incident surfaces is a structural problem that outlasts the particular criminals involved. When a call arrives appearing to come from a government official at an official number, recipients have no reliable way to verify it. There is no ledger of what a voice model was used for, no record of calls made from a given system, and no mechanism to confirm that the voice on the line belongs to the person it claims to be. A provable record of what a system did, when, and on whose authorization would not have prevented the technology from existing, but it would have given both investigators and targets something concrete to check, closing the window between the moment fraud begins and the moment it becomes visible.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.