Why in news?
India’s securities regulator warned companies about a growing “boss scam”. Criminals impersonate senior executives and demand urgent financial action. Some attacks use deepfake calls or stolen messaging sessions. The regulator asked firms to strengthen payment verification.
Background
A boss scam is executive impersonation fraud; the criminal pretends to be a trusted senior organisational officer.
The target is usually someone who can approve or process payments.
The fraudster creates urgency, secrecy and fear of disobeying a superior.
These pressures can make an employee ignore ordinary verification steps.
The fraud resembles business email compromise, but it can use many communication platforms.
Who issued the latest warning?
The Securities and Exchange Board of India is shortened to SEBI; it regulates markets and protects investor interests.
SEBI issued the warning on 17 July 2026 after the Indian Cyber Crime Coordination Centre raised an alert.
This centre is shortened to I4C and operates under the Union Home Ministry.
SEBI addressed regulated entities and listed companies because attackers were targeting their senior personnel.
Who are the usual targets?
- Chief financial officers and finance executives may control large payments, records and bank instructions.
- Accounts staff may receive urgent payment requests from senior officers.
- Secretarial teams may handle confidential company information.
- Senior managers may have authority over vendors and major transactions.
A chief executive officer is shortened to CEO; a managing director is shortened to MD.
Criminals commonly copy the name, photograph or communication style of these officers.
How does the first attack method work?
- The attacker studies the company and gathers public photographs, videos and voice recordings.
- Artificial intelligence may create a fake voice or video for a convincing call or message.
- The supposed boss describes a confidential transaction and orders the target to avoid colleagues.
- Money is transferred before independent verification occurs.
A deepfake is synthetic audio, video or imagery that convincingly imitates a real person.
Attackers may also create fake groups on WhatsApp, Microsoft Teams or similar platforms.
Several fake participants can make the request appear internally approved.
How can market-sensitive information become part of the story?
The fraudster may claim secrecy protects a deal; the request may mention Unpublished Price Sensitive Information.
This term is shortened to UPSI; it means non-public information that could materially affect a security’s price.
Examples include unpublished financial results, mergers or major business changes.
A criminal uses this language to discourage the employee from checking with others.
Warning sign: Genuine confidentiality never removes the need for an authorised payment-verification process.
How does the second attack method work?
- The target receives a ZIP file containing executable or Dynamic Link Library components.
- Opening the file installs malware that steals an active WhatsApp Web session token.
- The criminal uses the live session to send payment directions to accounts staff.
- The money reaches accounts controlled by the criminal network.
An executable file contains instructions that a computer can run.
A Dynamic Link Library contains code that software can load when required.
A session token proves that a user has already logged into an online service.
Stealing that token can bypass the login screen; the attacker may also alter contacts on the compromised device.
A criminal number can then appear under the CEO’s or MD’s name.
What is a mule account?
A mule account receives or moves money for a criminal operation.
Its holder may be involved or deceived; fraudsters quickly divide stolen funds among several such accounts.
This movement makes recovery and tracing more difficult.
Does the boss’s account always need to be hacked?
No; convincing impersonation can succeed without compromising the real executive’s account.
A copied photograph and similar display name may be enough.
A fake email address may differ from the genuine address by one character.
Deepfake audio can imitate the executive during a short call.
Some attacks do compromise an account or active session, but this is not essential.
Key clarification: A boss scam describes the impersonation method; it does not always prove that the boss was hacked.
Which warning signs should employees notice?
- The request demands immediate action outside the usual approval process.
- The sender insists that nobody else should know.
- The payment goes to a new or recently changed account.
- The message arrives from an unfamiliar number or slightly altered address.
- The sender discourages telephone verification or requests installation of unexpected software.
- The language, timing or behaviour differs from the executive’s normal practice.
How can organisations prevent the fraud?
- Employees should call the executive through a previously known number.
- Large payments should require approval from more than one authorised person.
- Bank-detail changes should be confirmed through a separate communication channel.
- Staff should never rely solely upon a digital message.
- Unknown executable files should not be opened or installed.
- Companies should log out unused WhatsApp Web sessions and regularly train finance and accounts teams.
- Payment systems should retain strong audit trails and transaction alerts.
Independent verification means checking through a channel not supplied by the suspected sender.
For example, staff should use the company directory rather than the number inside the message.
What should a victim do?
The victim should immediately contact the bank and request transaction blocking.
Cyber financial fraud can be reported through the national helpline number 1930.
A complaint can also be filed through the National Cyber Crime Reporting Portal.
The affected organisation should preserve messages, numbers, files and transaction records.
Rapid reporting improves the chance of freezing funds before they move further.
Conclusion
Boss scams exploit trust more than technical weakness; a short independent check can stop a large and irreversible payment.