Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Is That Really Your CEO on the Call? Microsoft Teams Gets Deepfake Detection After a €95 Million Voice-Clone Heist (AI Trends, 9 October 2026)

  1. Home   »  
  2. Is That Really Your CEO on the Call? Microsoft Teams Gets Deepfake Detection After a €95 Million Voice-Clone Heist (AI Trends, 9 October 2026)

Is That Really Your CEO on the Call? Microsoft Teams Gets Deepfake Detection After a €95 Million Voice-Clone Heist (AI Trends, 9 October 2026)

October 9, 2026October 9, 2026 admincybersecurityTagged AI detection, AI security, AI trends, CEO fraud, deepfakes, financial services security, Microsoft Teams, payment fraud, phishing, proof of human, voice cloning

What’s trending in AI on 9 October 2026: The face on your next video call may not belong to the person you think it does, and Microsoft has just admitted as much in product form. On 8 October BleepingComputer reported that Microsoft Teams will add support for certified third-party deepfake detection and a built-in impersonation protection feature, both listed on the Microsoft 365 Roadmap for general availability in November 2026. The timing is not a coincidence. In the past two weeks we have learned that an Italian private bank wired about €95 million after its chairman heard an AI-cloned lawyer’s voice, that 74% of US security leaders say they faced a suspected deepfake attack in the last year, and that 81% of finance leaders report AI-enabled fraud attempts. Below: what Teams is adding, what the new numbers say, how the €95 million fraud actually worked, what detection can and cannot do, and a verification ladder you can adopt before the feature arrives.

Key takeaways

  • Teams is getting deepfake defenses. Certified providers will analyze meeting audio and video for synthetic or manipulated media and send signals that Teams turns into in-meeting warnings and controls. A separate feature will flag deceptive organizers or participants. Both target November 2026.
  • The losses are real and large. Fideuram, Intesa Sanpaolo’s private bank, sent about €95 million in 11 transfers after a fake CEO WhatsApp and a cloned lawyer’s voice. Roughly €53 million has been recovered, according to Reuters.
  • Most security leaders have seen it. Pindrop’s 2026 Deepfake Readiness Index found 74% of 250+ US security leaders encountered a suspected deepfake attack, and one in four of those hit lost more than $1 million in a single incident.
  • Detection is a backstop, not a control. The Fideuram fraud used WhatsApp and a phone call, not a Teams meeting. Process rules such as call-backs and dual approval stop fraud on every channel.
  • Act before November. Map which payments and approvals can be authorized on a call, add out-of-band verification, and decide how your team will respond when a detection banner appears.
Is that really your CEO on the call?Title card. Headline: Is that really your CEO on the call? Subhead: Microsoft Teams gets deepfake detection after a 95 million euro voice-clone fraud. Three tags: Teams deepfake detection targeted for November 2026; about 95 million euros sent by Fideuram after a cloned voice call; 74 percent of US security leaders hit by a suspected deepfake. Illustration of a video-call window showing a stylised face split into a solid half and a wireframe half, with an orange warning badge. Possible synthetic media ! AI TRENDS · 9 OCTOBER 2026 Is that really your CEO on the call? Microsoft Teams gets deepfake detection after a €95 million voice-clone fraud Teams deepfake detection targeted for November 2026 ~€95M wired by Fideuram after a cloned voice call 74% of US security leaders hit by a suspected deepfake Sources: BleepingComputer (8 Oct 2026), Reuters via Private Banker International, Pindrop via Infosecurity Magazine delana.co
Deepfake detection is coming to Teams meetings in November. The frauds it is meant to stop are already happening on every channel.

1. What Microsoft is adding to Teams

According to BleepingComputer, two new entries on the Microsoft 365 Roadmap describe the changes. The first (roadmap item 573451) lets organizations plug synthetic audio and video detection from certified third-party providers into Teams meetings. Those tools analyze the meeting’s media streams for signs that a voice or face has been generated or manipulated, then pass detection signals back to Teams, which surfaces them as in-meeting experiences and controls. The second (roadmap item 573157) is impersonation protection: Teams will flag possible impersonation by deceptive organizers or participants and show warnings and risk indicators, so people can judge a suspicious identity before joining a meeting or while it is running.

Both features are in development and are expected to reach general availability in November after a worldwide rollout. Microsoft has not yet named the certified detection providers, said how licensing will work, or published detailed admin controls, so expect more detail closer to launch. They extend a run of Teams hardening this year, summarised in the table below.

FeatureWhat it doesWho provides itStatus
Deepfake detection support (roadmap 573451)Analyzes meeting audio and video for synthetic or manipulated media; Teams shows signals and controlsCertified third-party providers (not yet named)In development, GA targeted November 2026
Impersonation protection (roadmap 573157)Flags deceptive organizers or participants with warnings and risk indicatorsMicrosoft, built into TeamsIn development, GA targeted November 2026
External bot blockingMeeting protection policy that blocks identified external bots from joiningMicrosoftRolling out since August
Suspicious guest invitation reportingLets users report dubious guest invites from inside TeamsMicrosoftFrom November
Compiled from BleepingComputer reporting on the Microsoft 365 Roadmap, 8 October 2026.

The design choice matters. Rather than building one detector, Microsoft is opening a slot for specialist vendors, which means your organization will likely have to choose, buy and govern a provider that sees the audio and video of your meetings. That is a privacy and procurement decision as much as a security one.

2. Why now: the numbers behind the feature

Two surveys published in the past fortnight show how common these attacks have become. The 2026 Pindrop Deepfake Readiness Index, reported by Infosecurity Magazine on 28 September, surveyed more than 250 US security leaders. 74% said they had encountered a suspected deepfake attack in the previous 12 months. Among those hit, one in four reported losses above $1 million from a single incident, counting direct losses, remediation and staff time. 93% worried their organization is not prepared, and three in four believed it would take a leader actually being impersonated before deepfakes became a board-level issue. Pindrop’s Elie Khoury put the problem simply: attackers now “impersonate the human those controls are designed to trust.”

The second survey comes from Certos, the fraud-prevention brand of Early Warning Services, published on 8 October. It polled 230 finance leaders at Fortune 500 companies, venture-backed firms and charities in August, excluding banks and AI providers. 81% reported attempted or suspected AI-enabled fraud in the past year and 84% said it is harder to detect than traditional fraud. Most striking: while 87% described themselves as prepared, only about half were confident they could spot a fraudulent attempt before money left the organization. These are self-reported figures, not verified losses, but the direction is consistent.

Deepfake and AI fraud survey results, autumn 2026Horizontal bar chart, percentages. Pindrop 2026 Deepfake Readiness Index, over 250 US security leaders: 74 percent encountered a suspected deepfake attack in the last 12 months; 93 percent worry they are not prepared; 25 percent of those hit lost more than 1 million dollars in one incident. Certos survey of 230 finance leaders: 81 percent saw attempted or suspected AI-enabled fraud; 84 percent say it is harder to detect; about 50 percent are confident they could spot fraud before money leaves.Most leaders have seen it. Half could miss it.Share of respondents, %. Bars drawn to scale (max 100). PINDROP · 250+ US SECURITY LEADERS Suspected deepfake attack, past year74% Worry they are not prepared93% Of those hit: lost $1M+ in one incident25% CERTOS · 230 FINANCE LEADERS Attempted or suspected AI fraud81% Say AI fraud is harder to detect84% Confident they’d catch it in time~50% Sources: Pindrop 2026 Deepfake Readiness Index via Infosecurity Magazine (28 Sep 2026); Certos survey via inkl (8 Oct 2026). Self-reported.delana.co
Two separate surveys, one picture: deepfake and AI-enabled fraud attempts are now the norm, and confidence in catching them in time is low.

Microsoft’s own threat research points the same way. Its 2026 Digital Defense Report argued that AI has given attackers a head start, and impersonation is one of the cheapest ways to use it.

3. Anatomy of a €95 million voice-clone fraud

The case that has made boards pay attention is Fideuram, the private-banking arm of Italy’s Intesa Sanpaolo. Reuters first reported it on 28 September, and Greek Reporter and others have since added detail from Italian court-linked reporting. Here is how it unfolded, based on those accounts.

On 23 February 2026, Fideuram’s then-chairman, Paolo Molesini, received a WhatsApp message that appeared to come from Intesa Sanpaolo CEO Carlo Messina. It described a confidential international acquisition and asked for urgent help with a payment. A follow-up phone call then appeared to come from a senior partner at a major law firm, whose voice the fraudsters had reportedly cloned with AI. The lawyer had nothing to do with it. Molesini received legal-looking paperwork, including a confidentiality agreement and a purported power of attorney. Meanwhile, the bank’s treasury team was contacted by a CEO impersonator and told to expect urgent instructions. Over 23–25 February, about €95 million left in 11 transfers to accounts routed through Portugal, China and Hong Kong.

How the Fideuram voice-clone fraud workedFive-step timeline. Step 1: WhatsApp message from a fake Intesa Sanpaolo CEO about a confidential acquisition. Step 2: phone call from an AI-cloned voice of a senior law-firm partner confirming the request. Step 3: forged confidentiality agreement and power of attorney. Step 4: treasury team primed by a CEO impersonator to expect urgent instructions. Step 5: 11 transfers totalling about 95 million euros over 23 to 25 February 2026. Outcome: uncovered when the real CEO said he never asked; about 53 million euros recovered per Reuters. Note: no video call and no system breach were involved.Five steps, three channels, no hackingFideuram (Intesa Sanpaolo), 23–25 February 2026 1WhatsAppfrom a fakegroup CEO 2Phone callAI-cloned voice ofa law-firm partner 3PaperworkNDA and forgedpower of attorney 4Treasury primed“expect urgentinstructions” 511 transfers~€95M to Portugal,China, Hong Kong HOW IT WAS CAUGHTThe real Fideuram CEO contacted the chairman,who checked with the group CEO: no such request. THE OUTCOME~€53M recovered (Reuters); roughly €36–39Mstill missing, partly converted to crypto. No video call and no system breach: Intesa Sanpaolo classed it as social-engineering fraud. Sources: Reuters via Private Banker International (28 Sep 2026); Greek Reporter (5 Oct 2026). Figures vary by source.delana.co
The fraud combined a messaging app, a cloned voice and forged documents. Each step made the next one more believable.

The fraud unravelled when Fideuram’s real CEO contacted Molesini, who then checked directly with Messina, who said he had never asked for any such transaction. Reuters reported that about €53 million has been recovered with help from authorities in China, Portugal and Italy; other reporting puts the unrecovered amount at roughly €36–39 million, some of it converted to cryptocurrency. Intesa Sanpaolo said its systems were not breached, and Molesini, who stepped down in March citing personal reasons, has been treated as a victim rather than a suspect. Milan prosecutors are investigating.

Notice what is missing: there was no video call, and nothing a Teams detector would have seen. The attackers won by stacking three believable signals, a familiar name on WhatsApp, a familiar voice on the phone and official-looking documents, while priming a second team so that nobody questioned the instructions. That is classic business email compromise, upgraded with a cloned voice. We covered the same pattern in Social Engineering Deception in 2025; the difference now is that the voice confirming the request can be faked too.

4. It is not only the boardroom

Fideuram is the largest recent case, but the same toolkit is hitting governments, investors and families. The table below lines up four cases from this year by the channel used and the control that failed.

CaseWhen reportedChannelLossWhat would have stopped it
Fideuram (Intesa Sanpaolo), Italy28 Sep 2026WhatsApp, cloned-voice phone call, forged documents~€95M (about €53M recovered)Call-back to a known number; independent second approver
Singapore “PM Wong” Zoom scam17 May 2026WhatsApp invite, then a Zoom call with deepfaked officialsAt least S$4.9M (US$3.8M)Verifying the invite through official channels
Ards and North Down, Northern IrelandSeptember 2026AI-generated celebrity video ad, WhatsApp, remote access£250,000Checking FCA authorisation; never granting remote access
California “virtual kidnapping”7 Oct 2026Phone call with a cloned voice of a daughter$5,400Calling the relative directly; a family code word
Compiled from Reuters via Private Banker International, South China Morning Post, The Irish News and Fox News. Losses as reported.

The details differ, but the playbook rhymes. In Singapore, victims were invited by a fake cabinet secretary to a Zoom call full of deepfaked officials. In Northern Ireland, a victim was coached over WhatsApp into borrowing money and granting remote access; police warned that a celebrity endorsement “should never be regarded as proof that an investment is genuine.” In California, Fox News reported a caller kept a Navy veteran on the phone for about five and a half hours, playing what sounded like her daughter crying.

The common thread is not the medium. It is urgency, secrecy and a single channel of verification controlled by the attacker. Our earlier pieces on voice-cloning rights and the proof-of-human problem explain why a familiar voice or face can no longer serve as an identity check on its own.

5. What detection can and cannot do

Deepfake detection inside Teams is useful. It watches exactly the moment fraudsters rely on: a live call in which someone senior asks for something urgent. A banner warning that a participant’s audio looks synthetic gives an employee permission to pause, which is often all that is needed. Impersonation protection could also catch lookalike external accounts before anyone joins.

How Teams deepfake detection is designed to work, and where it stopsFlow diagram. A Teams meeting’s audio and video go to a certified third-party detection provider, which analyzes them for synthetic or manipulated media and sends detection signals back to Teams. Teams then shows in-meeting warnings and controls to participants. A separate built-in feature, impersonation protection, flags deceptive organizers or participants before or during the meeting. Below, a grey box labelled outside its view lists channels detection does not cover: WhatsApp and SMS, phone calls, email, and other video platforms.Inside the meeting, a second pair of eyesBased on Microsoft 365 Roadmap descriptions; provider names and admin controls not yet published Teams meetingaudio + video streams Certified provideranalyzes for synthetic ormanipulated media Signals back to Teamsin-meeting warnings and controls Plus impersonation protection: flags deceptive organizers or participants before or during a meeting OUTSIDE ITS VIEWWhatsApp and SMS · phone calls · email · Zoom and other platforms · forged documents Source: BleepingComputer on Microsoft 365 Roadmap items 573451 and 573157 (8 Oct 2026). Simplified illustration.delana.co
Detection watches the meeting. Most of the Fideuram fraud happened on channels it will never see.

But detection has limits that every buyer should understand. It only covers the channel it is plugged into, and recent frauds have used WhatsApp, phone calls, Zoom and forged PDFs. Detectors produce false positives and false negatives, and attackers will tune their tools against whichever detectors become popular. A warning is also only as good as the response to it: if staff have no agreed next step, a banner becomes another notification to dismiss. Finally, a third-party provider analyzing your meeting media is a new data processor, so you will need to review where it processes audio and video, how long it keeps anything, and whether it trains on your data, in the same way we recommended for any AI tool in our shadow AI guide.

There is an insurance angle too. Policies often treat a transfer authorized by a deceived employee differently from a hack, so check how yours handles social-engineering fraud; see our note on cyber insurance and AI exclusions.

6. The verification ladder: match the check to the stakes

The cheapest defense against a perfect fake is a rule that does not depend on spotting it. Instead of one blanket policy, set verification steps that rise with the value and reversibility of the request. Climb one rung for every red flag you see: urgency, secrecy, a new payee, a new channel or a request to bypass normal approval.

The verification ladderA four-rung staircase rising from left to right. Rung 1, routine requests: confirm in the normal system of record. Rung 2, changes to payee details, passwords or access: call back on a number from your own records, never one supplied in the request. Rung 3, payments above your threshold or anything urgent and confidential: call-back plus a second approver who was not on the original call. Rung 4, very large or irreversible transfers: call-back, dual approval, a shared code phrase or in-person confirmation, and a mandatory cooling-off delay. Note: climb one rung for each red flag such as urgency, secrecy, a new payee or a new channel.The verification ladderClimb one rung for each red flag: urgency, secrecy, new payee, new channel 1 · RoutineConfirm in the normalsystem of record 2 · ChangesPayee details, access,passwords: call back on anumber from your records 3 · MaterialAbove threshold or urgentand confidential: call-backplus a second approver whowas not on the call 4 · CriticalLarge or irreversible:call-back, dual approval,code phrase or in-personcheck, and a cooling-offdelay before release Delana guidance, informed by PSNI, Fox News/FBI virtual-kidnapping advice and AI Governance Institute recommendations. Not legal advice.delana.co
The higher the stakes, the more independent channels must agree before money moves. None of these rungs depends on spotting a fake.

Turn the ladder into practice with these steps, in this order:

  1. First, map your “call-authorized” decisions. List every payment, contract approval, payee change, password reset and access grant that someone can currently trigger on the strength of a call, a video meeting or a chat message. This is your exposure list.
  2. Rung 2 – Make call-backs mandatory for any change. For new payees, changed bank details and account recovery, the employee hangs up and calls back on a number taken from your own records, never one in the message. Publish this rule so executives expect it and do not take offence.
  3. Rung 3 – Add an independent second approver above a threshold. Set a value above which a payment needs approval from someone who was not on the original call or thread. Fideuram’s treasury team had been primed by the same fraudsters; independence is the point.
  4. Rung 4 – Build in a cooling-off delay for the biggest moves. For transfers that would be hard to reverse, require a short hold before release plus a code phrase or in-person confirmation. Urgency is the attacker’s main tool; a delay removes it.
  5. Decide what a detection banner means before November. Agree that a deepfake or impersonation warning in Teams means “stop, end the call, verify through rung 2 or higher”, and brief finance, legal and executive assistants on it.
  6. Review the detection provider like any data processor. When certified providers are named, check where meeting media is processed, how long anything is retained, whether it is used for training and how false positives are handled.
  7. Rehearse it once. Run a short tabletop in which a “CEO” on a call asks for an urgent confidential transfer. Our earlier article, Deepfakes Are on the Rise, includes scenarios you can adapt.

7. What to watch next

  • Which providers Microsoft certifies. The list, and their pricing and data terms, will decide how many organizations actually switch detection on.
  • Whether Zoom, Google Meet and Webex follow. Attackers will move to whichever platform has the weakest checks, so cross-platform support matters.
  • The Fideuram investigation. Milan prosecutors are tracing the remaining funds; any charges or recovered sums will show how traceable cloned-voice fraud really is.
  • Regulatory pressure on payment controls. Expect financial regulators and auditors to ask how firms verify instructions received by voice or video, not just by email.

Frequently asked questions

Is Microsoft Teams adding deepfake detection?

Yes. According to the Microsoft 365 Roadmap, as reported by BleepingComputer on 8 October 2026, Teams will support certified third-party tools that analyze meeting audio and video for synthetic or manipulated media, plus a built-in impersonation protection feature. Both are targeted for general availability in November 2026.

How will Teams deepfake detection work?

Certified providers will analyze the media in a Teams meeting and send detection signals back to Teams, which will show in-meeting warnings and controls. Impersonation protection will separately flag deceptive organizers or participants with risk indicators before or during a meeting. Microsoft has not yet named the providers or published licensing details.

What happened in the Fideuram deepfake fraud?

In February 2026 fraudsters posing as Intesa Sanpaolo’s CEO on WhatsApp, backed by an AI-cloned voice of a law-firm partner and forged documents, persuaded Fideuram’s then-chairman to authorize about €95 million in 11 transfers. Reuters reported about €53 million has been recovered. The bank said its systems were not breached.

How common are deepfake attacks on businesses?

Pindrop’s 2026 Deepfake Readiness Index found 74% of more than 250 US security leaders encountered a suspected deepfake attack in the past 12 months, and one in four of those hit lost over $1 million in a single incident. A Certos survey found 81% of finance leaders reported attempted or suspected AI-enabled fraud.

Will deepfake detection stop CEO fraud?

Not on its own. Detection only covers the platform it is built into, and many frauds use WhatsApp, phone calls, email or other video tools. It can also miss fakes or raise false alarms. Process controls such as call-backs to known numbers, independent second approvers and cooling-off delays protect every channel.

What should a business do before Teams deepfake detection arrives?

List every payment or approval that can be authorized on a call, require call-backs for payee or access changes, add an independent second approver above a set value, and agree that any detection warning means ending the call and verifying another way. This is general guidance, not legal advice.


Sources

  • BleepingComputer: Microsoft Teams to get support for third-party deepfake detection tools (8 Oct 2026)
  • AI Governance Institute: Microsoft Teams deepfake detection arrives in November, demanding payment control review (8 Oct 2026)
  • Infosecurity Magazine: Pindrop 2026 Deepfake Readiness Index coverage (28 Sep 2026)
  • inkl: Four in five finance leaders report AI fraud attempts as deepfake fears grow (8 Oct 2026)
  • Private Banker International (citing Reuters): Intesa’s private banking arm hit by AI scam (28 Sep 2026)
  • Greek Reporter: Scammers steal $108 million from Italian bank using AI-cloned voices (5 Oct 2026)
  • South China Morning Post: How a victim lost US$3.8 million in Singapore deepfake Zoom scam (17 May 2026)
  • The Irish News: PSNI urges vigilance after investment fraud victim loses £250,000 (September 2026)
  • Fox News: AI voice scam traps mom in 5-hour kidnapping nightmare (7 Oct 2026)

Post navigation

Previous: OpenAI’s $20 Billion Revenue Gap: What “Annualized Revenue” Hides, Why AI Stocks Fell and How to Stress-Test Your AI Vendors (AI Trends, 9 October 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC