Mon, 14 Sep 2026 · LIVE
Updated Jul 17, 2026 · 18:45
Technology News Updated Jul 17, 2026

SEBI Warns Companies Against 'Boss Scam' Cyber Fraud Targeting CEOs

Capital markets regulator SEBI has warned listed companies about a new cyber fraud called the 'Boss Scam', where criminals impersonate CEOs or senior officials to trick employees into transferring funds. The advisory follows a rise in such frauds flagged by the Indian Cyber Crime Coordination Centre, with methods including email, WhatsApp, and Microsoft Teams. In sophisticated cases, fraudsters use AI tools like voice cloning and deepfake video calls to make impersonations seem authentic. SEBI advises independent verification of all fund transfer requests and cautions against authorizing payments based solely on social media messages.

SEBI warns firms against 'Boss Scam' cyber fraud targeting CEOs

Mumbai, July 17

Capital markets regulator Securities and Exchange Board of India on Friday cautioned listed companies and regulated entities against an emerging cyber fraud known as the "Boss Scam", in which cybercriminals impersonate chief executive officers, managing directors or other senior officials to trick employees into transferring funds.

The advisory comes after the Indian Cyber Crime Coordination Centre (I4C) flagged a rise in CEO and MD impersonation frauds targeting organisations through email, WhatsApp, Microsoft Teams and other social media platforms.

According to SEBI, fraudsters pose as senior executives and send urgent messages or make calls instructing finance or accounts personnel to transfer money to specified bank accounts.

"Fraudsters are targeting CEO or high ranking official via email or WhatsApp by impersonating them. The communication through email/ WhatsApp/Microsoft Teams/other social media platforms with their subordinates or counterparts, directs them to carry out instructions given to them resulting in transfer of funds to fraudsters," SEBI said in its advisory.

In some cases, cybercriminals use artificial intelligence-based tools such as voice cloning and deepfake video calls to make the impersonation appear authentic.

The regulator also warned about another modus operandi in which fraudsters send a compressed ZIP file containing malicious software.

Once opened on a Windows device, the malware can hijack an active WhatsApp Web session, enabling cybercriminals to access the victim's account and send fraudulent payment instructions to finance teams.

SEBI said fraudsters may also manipulate contact lists on compromised devices by saving their own phone numbers under the names of CEOs or managing directors, making fraudulent calls or messages appear genuine.

To prevent such incidents, SEBI advised listed entities and regulated organisations to independently verify all fund transfer requests received through email, WhatsApp or other social media platforms by directly contacting the concerned senior official through a trusted communication channel.

The regulator also urged organisations not to authorise fund transfers solely based on messages received through social media platforms and to avoid installing executable or compressed files without first verifying the sender's identity.

In addition, SEBI recommended that organisations regularly log out of inactive WhatsApp Web sessions to minimise the risk of account compromise.

— IANS

Reader Comments

Priya S

The regulator should also mandate two-factor verification for all fund transfers above a certain amount. Many Indian companies, especially smaller ones, still rely on a single email or WhatsApp message. This is not enough anymore. Cyber criminals are getting too sophisticated.

Vikram M

Good advisory from SEBI. But honestly, in my company, we've been doing this for years - any fund transfer request, even from the CEO himself, has to be verified via a phone call on his known number. It takes 2 minutes and can save crores. Basic cyber hygiene, people!

Rohit P

The best part? These fraudsters are using Microsoft Teams and WhatsApp - exactly the tools we were forced to adopt during COVID. Now our own digital transformation has become an attack vector. Indian firms need to invest in proper cybersecurity training for ALL employees, not just IT staff.

Kavya N

Honestly, the weakest link in any organization is the human being. No amount of technology can protect against someone who is too scared to question a "boss" on WhatsApp. Companies need to create a culture where it's okay to verify. In India, we are too hierarchical - that mindset needs to change.

Siddharth J

Wait, so they can hijack WhatsApp Web by sending a ZIP file? That's terrifying. So many of us keep WhatsApp Web logged in permanently on office laptops. SEBI should also advise companies to implement strict policies around browser extensions and file downloads. Common sense but needs to be said.

We welcome thoughtful discussions from our readers. Please keep comments respectful and on-topic.

Reader Voices

Leave a comment

Be kind. Add to the conversation. 0/50
Thank you — your comment has been submitted.
JS blocked