A €95 Million Deepfake, a 495% Fraud Surge, and DORA With Its Gloves Off

As of this week, the question is no longer whether deepfakes work in banking. The question is which bank is next, and whether its regulator will let the answer go quietly.
The number that changed the conversation
Earlier this week, Italy's largest banking group, Intesa Sanpaolo, confirmed that its private-banking arm, Fideuram, had been the victim of an AI-enabled fraud that saw almost €95m leave the business. According to FinTelegram, the attackers impersonated senior executives and advisers using synthetic voice and video, convincing internal staff to authorise transfers that would normally have required multiple sign-offs.
This was not a classic cyberattack. No ransomware. No stolen database. The attackers did not need to break the perimeter. They walked in through the identity layer, wearing someone else's face.
For a European bank of Intesa Sanpaolo's size, a €95m single-incident loss is a reportable, board-level event. For the rest of the industry, it is the proof point that stops the it-will-not-happen-to-us sentiment in its tracks.
The verification layer is the new perimeter
The Fideuram incident fits a pattern that has been forming all year. According to Pindrop's enterprise deepfake report, released on 29 September 2026, nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year. Industry data cited by Proof puts deepfake fraud at 6.5 per cent of global fraud attempts, up from 0.1 per cent three years ago.
Translation: what used to be a novelty category has become a mainstream attack surface.
Why the identity layer is so attractive
Banks have poured billions into perimeter defences: endpoint detection, network segmentation, SIEM dashboards, red teams. Those investments made the obvious ways in expensive. The identity layer, by contrast, is still largely built on assumptions that no longer hold:
That a live video call with a known executive is proof of presence. It is not. A $5 synthetic clip, according to industry pricing cited by FinanceX Magazine, can bypass many standard biometric onboarding checks.
That a voiceprint approval is final. It is not. Generative audio models trained on a few minutes of podcast or earnings-call recording can clone a C-suite voice at a fidelity that defeats most voice-biometric systems in production today.
That a KYC vendor's output can be trusted downstream. That assumption cracked over September 2026, with multiple breaches at identity vendors reported across the sector.
Put simply, the verification layer has become the breach.
DORA, finally with teeth
The regulatory backdrop has sharpened. The EU's Digital Operational Resilience Act (DORA), fully applicable since January 2025, has moved out of the prepare-for phase and into the be-audited-under phase. National competent authorities across the EU are running active enforcement reviews, and the first supervisory decisions are expected before year-end, according to analysis from FinanceX Magazine.
DORA's bite comes from three places:
Mandatory incident classification and reporting on tight timelines, which strips firms of the ability to quietly absorb a loss.
ICT third-party risk oversight, which puts regulators inside the vendor contracts, not just at the firm's own perimeter.
Operational resilience testing (TLPT), which forces firms to prove, by exercise, that they can withstand severe but plausible scenarios. A €95m deepfake fraud now qualifies as plausible in any serious scenario catalogue.
What enforcement looks like in practice
Early guidance from EU authorities suggests the first enforcement wave will not focus on fines alone. Expect public findings on third-party risk governance, especially around KYC and identity vendors, and formal requirements for independent reverification layers that do not rely on a single video or voice modality.
That matters because many banks still have a KYC stack whose weakest link is a single vendor API. DORA regulators are now empowered to ask, loudly and in writing, why.
eIDAS 2.0 and the identity wallet moment
Parallel to DORA, eIDAS 2.0 is reshaping the identity side. The EU Digital Identity Wallet is hitting critical rollout milestones, with member states obliged to make a wallet available to every citizen in 2026. The wallet promises a cryptographically verifiable, user-held identity that is harder to spoof than a scan of a passport in a selfie.
For banks, that is a double-edged sword. In the long run, wallet-based identity reduces the attack surface. In the short run, it adds another vendor stack, another integration deadline, and another piece of plumbing to secure.
The quiet comeback of ransomware
Deepfakes have grabbed the headlines, but ransomware has not gone away. September 2026 saw the OneMain Financial breach move into class-action territory, with Murphy Law Firm announcing on 29 September that it is investigating claims on behalf of 16,988-plus affected individuals. The playbook (encrypt, exfiltrate, extort, then shame on a leak site) remains highly profitable, and remains the sector's second-biggest loss driver after fraud.
Together, deepfake fraud and ransomware form a pincer. One targets the people in the loop. The other targets the systems around them. Firms that treat the two as separate problems, with separate teams and separate budgets, tend to find out, expensively, that the attackers do not.
What good looks like
A short list, drawn from DORA-aligned best practice and the harder-earned lessons of recent incidents:
Treat identity as a layered, not a single-point, control. No single vendor, modality or signal should be able to authorise a material transfer on its own. Live video needs to be paired with transaction-aware, step-up signals and independent reverification.
Rehearse the human. The Fideuram attackers did not defeat a model. They defeated a workflow. Tabletop exercises that include synthetic voice and video, inside realistic internal calls, surface weaknesses that no technical scan will find.
Instrument the KYC vendor chain. Know, in writing, what every third-party identity provider can see, store and expose. Treat vendor breaches as your breaches. DORA already does.
Report fast, learn faster. The incident classification timelines in DORA leave no room for the old habit of settling the loss quietly. Firms that build muscle around rapid classification will suffer less, both financially and reputationally.
The take
The uncomfortable truth is that the financial sector's cybersecurity story in 2026 is less about zero days and more about trust layers that no longer hold. A €95m fraud at a European tier-one bank, a 495 per cent deepfake surge, a KYC vendor layer under siege, DORA regulators sharpening their pencils, and a new EU identity wallet landing on the same desks at the same time.
That is a lot of weather, all at once. The firms that come through this quarter with reputation and balance sheet intact will be the ones that stop treating identity as a procurement problem and start treating it as the perimeter.



