The Securities and Exchange Board of India (SEBI) has cautioned regulated entities and listed companies against a growing cyber fraud known as the “Boss Scam”, where fraudsters impersonate chief executives and senior officials to trick finance teams into transferring funds. In a press release issued on July 17, the market regulator said the Indian Cyber Crime Coordination Centre (I4C) had alerted it to the emerging threat, which increasingly relies on AI-generated deepfakes, voice cloning, malicious software, and social engineering to compromise organisations.
How the scam works:
- Fraudsters impersonate senior executives: Attackers pose as CEOs, Managing Directors, or other senior officials through email, WhatsApp, Microsoft Teams, or other messaging and communication platforms, instructing employees to carry out urgent financial transactions.
- Strategy A – AI-powered impersonation: Scammers use voice cloning, AI-generated video calls, or fake social media groups to impersonate company leaders. They direct finance officers to transfer funds to mule bank accounts, often claiming the transaction relates to Unpublished Price Sensitive Information (UPSI) and should remain confidential.
- Strategy B – Malicious ZIP archive: Fraudsters send a compressed .zip file containing a malicious .exe and .dll file. Once opened, the malware hijacks the victim’s WhatsApp Web session or compromises the entire device. Attackers then impersonate the executive from the employee’s own account or alter contact details to issue fraudulent payment instructions.
- The scammers’ goal: The objective in both cases is to manipulate finance personnel into transferring money to accounts controlled by the fraudsters.
What SEBI has advised:
- Verify instructions independently by calling senior officials before acting on requests received over WhatsApp, email, or social media platforms.
- Do not transfer funds solely on the basis of digital instructions.
- Avoid installing executable files unless the sender’s identity has been verified.
- Log out of inactive WhatsApp Web sessions to reduce the risk of account hijacking.
Also read:
Click Here For The Original Source.
