India’s markets regulator has put a name to the fraud wave hitting corporate finance desks. In an advisory issued on Friday, July 17, SEBI cautioned listed companies and all regulated entities against the so called Boss Scam, in which criminals impersonate a CEO, MD or other senior official and pressure employees into urgent fund transfers. The alert, reported by the Free Press Journal and Business Standard, follows a warning from the Indian Cyber Crime Coordination Centre (I4C) that executive impersonation attacks are rising sharply across email, WhatsApp, Microsoft Teams and social media. The most important line in the advisory is also the simplest: before moving any money, verify the request by calling the official directly.
| What happened | SEBI cautioned all listed companies and regulated entities against the Boss Scam, a wave of CEO and MD impersonation fraud targeting finance teams |
|---|---|
| Advisory issued | Friday, July 17, 2026, following an alert from the Indian Cyber Crime Coordination Centre (I4C) |
| Channels used | Email, WhatsApp, Microsoft Teams and social media platforms |
| Methods | AI voice cloning, deepfake video calls, WhatsApp Web hijack via malicious ZIP files, tampered contact lists saving fraudster numbers under executives’ names |
| SEBI’s safeguards | Verify transfers by calling the official on a known number, never move funds on messaging instructions alone, avoid unverified executables, log out of idle WhatsApp Web sessions |
| Report incidents | National cybercrime helpline 1930 or the Cyber Crime portal |
What exactly is the Boss Scam?
The mechanics are old fashioned social engineering with a new engine underneath. An employee in finance or accounts receives a message, or increasingly a call, that appears to come from the top of the organisation. The tone is urgent and confidential: a deal is closing, a vendor must be paid, the transfer cannot wait. Because the instruction seems to come from the boss, normal payment controls get skipped.
What has changed is the quality of the impersonation. According to the advisory, fraudsters are now using AI voice cloning and deepfake video calls to make the approach look and sound genuine. A convincing voice on the phone, or a familiar face on a hurried video call, defeats the informal check most employees rely on, which is simply recognising their own leadership. This is the same capability shift we examined in our opinion piece on why enterprises are not ready for deepfake attacks: the technology needed to fake a senior executive credibly has moved from specialist labs to commodity tools.
Globally, this family of fraud is tracked as business email compromise, and it remains one of the most expensive crimes on the internet. The FBI’s Internet Crime Complaint Center has attributed US$3.04 billion in reported losses to BEC in a single year, and that figure only counts complaints that were actually filed.
How does the WhatsApp malware variant work?
Alongside voice and video impersonation, the advisory describes a quieter technical route into the same outcome. Targets receive a compressed ZIP file that carries malicious software. Once the file is opened on a Windows machine, the malware hijacks any active WhatsApp Web session on that device.
From there the attacker does not need to imitate anyone. They are inside a real account, sending payment instructions to finance and accounts personnel from a genuine identity that colleagues already trust. The advisory also notes that fraudsters alter contact lists on compromised devices, saving their own numbers under the names of the CEO or MD so that a later call or message appears legitimate on screen. It is a reminder that the caller ID and the sender name are rendered by software, and software can be made to lie.
Why is SEBI treating impersonation fraud as a market issue?
A markets regulator stepping into what looks like a payments crime says something about scale. When I4C flags a fraud pattern strongly enough for SEBI to instruct every listed company and regulated entity, the problem has moved beyond isolated incidents into something that threatens corporate treasuries, and by extension shareholders.
It also fits a wider regulatory direction in India. As we covered in our analysis of India’s cybersecurity policy and CISO liability in 2026, regulators are steadily shifting cyber risk from an IT concern to a governance concern, with named executives expected to answer for failures. An advisory that tells boards to harden their payment verification culture sits squarely in that trend. Security leaders should read it less as a routine circular and more as an early marker of what examiners will ask about after the next incident.
The attacker side of the equation is moving just as fast. Our recent reporting found that AI now appears at every stage of the cyberattack kill chain, and executive impersonation is simply the stage where that capability cashes out.
What should finance teams and CISOs do now?
SEBI’s recommended safeguards are deliberately practical. Companies and regulated entities should:
- Independently verify any transfer request received over WhatsApp, email or social media by calling the concerned official directly on a known number
- Never move funds on the basis of social media or messaging instructions alone
- Refrain from opening or installing executable files without verifying the sender’s identity
- Log out of inactive WhatsApp Web sessions so a hijacked session cannot linger unnoticed
- Report incidents to the national cybercrime helpline 1930 or the Cyber Crime portal
The harder work is cultural. A callback rule only functions if a junior accounts executive feels safe delaying the CEO’s apparently urgent instruction, and that permission has to be granted loudly, from the top, before the attack arrives. This is where the industry conversation about moving from annual training to human risk management becomes concrete: the defence against the Boss Scam is not a firewall rule, it is a rehearsed verification habit in the finance team, measured and drilled like any other control.
For CISOs, the advisory is also a prompt to update the threat model conversation with leadership. As we argued in our look at what AI is changing for CISOs in 2026, the executive team is no longer just a stakeholder in security. Their voices, faces and identities are now attack surface.
The Boss Scam will not be the last advisory of its kind. As voice cloning and video synthesis keep improving, the gap between a real instruction and a fake one will keep narrowing, and the organisations that cope will be the ones that stopped trusting channels and started verifying people. SEBI has, in effect, told corporate India to make one phone call before every large transfer. It is cheap advice, and it may be the highest ROI control of the year.
Frequently asked questions
What is the Boss Scam?
A CEO impersonation fraud flagged by SEBI on July 17, 2026. Criminals pose as a company’s CEO or MD over email, WhatsApp, Teams or calls, increasingly using AI voice cloning and deepfake video, and pressure finance staff into urgent fund transfers to accounts they control.
What did SEBI advise companies to do about the Boss Scam?
Independently verify any transfer request received over WhatsApp, email or social media by calling the official on a known number, never move funds on messaging instructions alone, avoid opening unverified executable files, log out of idle WhatsApp Web sessions, and report incidents to the 1930 cybercrime helpline.
Why is CEO impersonation fraud harder to detect now?
Because AI voice cloning and deepfake video calls make the impersonation convincing enough to defeat informal recognition of a familiar voice or face. That shifts the only reliable defence from instinct to process: a rehearsed callback and verification habit inside the finance team.

Leave a Reply