Registrationwala
  • Update and Alerts
  • Become an Associate
  • Get a Quote
  • Login
  • Register

Securities and Exchange Board of India (SEBI) Warns Against Boss Scam

  • 22 Jul 2026
  • 43 Views

On 17 July 2026, the Securities and Exchange Board of India (SEBI), in its press release, issued a warning to regulated entities as well as the listed companies regarding the Boss Scam, also referred to as the CEO/MD impersonation fraud. It is an emerging trend in cybercrime.

How the Boss Scam is Carried Out 

The modus operandi (mode of operating) of the trending Boss Scam is outlined below:-

Target & Fraud Initiation

Under the boss scam, the fraudsters are targeting the CEOs or high-ranking executives by impersonating them via email or WhatsApp. The communication via email, WhatsApp, Microsoft Teams or other social media platforms with their subordinates/counterparts directs them to carry out certain instructions. Because of this, the funds get transferred to the fraudsters.

Deepfakes/Malicious Zip Archive for Impersonation

Fraudsters have been observed to be using two primary strategies:-

(a.) Strategy A:- Impersonation of Managing Directors (MDs) and Chief Executive Officers (CEOs) through deepfake technology, such as voice cloning and video calls that falsely represent these officials. They also create counterfeit social media groups to impersonate high-ranking officials. 

(b.) Strategy B:- Sending a compressed .zip file via message. This zip archive contains a malicious executable file (.exe) along with a Dynamic Link Library (.dll) file. As noted by I4C, the CEO may forward this message to finance officers. 

Instructions for Fund Transfers

Through Strategy A, the finance officer receives instructions to transfer funds to a designated mule account. These instructions may explicitly state that the transaction should not be shared, citing concerns about Unpublished Price Sensitive Information. As per the observations so far, such communications are conducted via messages/fake calls on social media platforms. 

Hijacking of WhatsApp Web

In Strategy B, if the finance officer extracts and executes a file on Windows desktop/laptop, a Trojan dropper is activated. This malware compromises systems and hijacks active WhatsApp Web session tokens. As a result, the fraudster gains access to the finance officer's WhatsApp account and contacts other accounts/finance employees, instructing them to make immediate payments to specified mule bank accounts. 

Furthermore, if fraudster gains complete control of device, they may secretly modify contact list, saving their own number under the name of CEO or MD. They then use this disguised number to instruct finance officer to transfer funds.

SEBI’s Advice to Regulated Entities and Listed Companies

SEBI has advised the regulated entities and listed companies to:-

  • Remain cautious and cross-verify any requests received via WhatsApp, email or social media by calling a senior colleague.

  • Do not transfer funds solely on the basis of instructions received via social media platform.

  • Avoid installing executables without verifying sender's identity or confirming through a phone call, even if request seems to come from someone familiar.

  • Log out of any WhatsApp Web sessions that are not actively in use.

  • Report any fraudulent apps/scam incidents immediately by calling 1930 or visiting Cybercrime Portal @ www.cybercrime.gov.in.

 

Source:- SEBI

Comments

No comments yet.


Leave a Comment

Want to know More ?

What's Latest Post In Registrationwala

Browse Our Services

Subscribe

Subscribe to our newsletter

Transform your Business.

Top