On 17 July 2026, the Securities and Exchange Board of India (SEBI), in its press release, issued a warning to regulated entities as well as the listed companies regarding the Boss Scam, also referred to as the CEO/MD impersonation fraud. It is an emerging trend in cybercrime.
The modus operandi (mode of operating) of the trending Boss Scam is outlined below:-
Under the boss scam, the fraudsters are targeting the CEOs or high-ranking executives by impersonating them via email or WhatsApp. The communication via email, WhatsApp, Microsoft Teams or other social media platforms with their subordinates/counterparts directs them to carry out certain instructions. Because of this, the funds get transferred to the fraudsters.
Fraudsters have been observed to be using two primary strategies:-
(a.) Strategy A:- Impersonation of Managing Directors (MDs) and Chief Executive Officers (CEOs) through deepfake technology, such as voice cloning and video calls that falsely represent these officials. They also create counterfeit social media groups to impersonate high-ranking officials.
(b.) Strategy B:- Sending a compressed .zip file via message. This zip archive contains a malicious executable file (.exe) along with a Dynamic Link Library (.dll) file. As noted by I4C, the CEO may forward this message to finance officers.
Through Strategy A, the finance officer receives instructions to transfer funds to a designated mule account. These instructions may explicitly state that the transaction should not be shared, citing concerns about Unpublished Price Sensitive Information. As per the observations so far, such communications are conducted via messages/fake calls on social media platforms.
In Strategy B, if the finance officer extracts and executes a file on Windows desktop/laptop, a Trojan dropper is activated. This malware compromises systems and hijacks active WhatsApp Web session tokens. As a result, the fraudster gains access to the finance officer's WhatsApp account and contacts other accounts/finance employees, instructing them to make immediate payments to specified mule bank accounts.
Furthermore, if fraudster gains complete control of device, they may secretly modify contact list, saving their own number under the name of CEO or MD. They then use this disguised number to instruct finance officer to transfer funds.
SEBI has advised the regulated entities and listed companies to:-
Remain cautious and cross-verify any requests received via WhatsApp, email or social media by calling a senior colleague.
Do not transfer funds solely on the basis of instructions received via social media platform.
Avoid installing executables without verifying sender's identity or confirming through a phone call, even if request seems to come from someone familiar.
Log out of any WhatsApp Web sessions that are not actively in use.
Report any fraudulent apps/scam incidents immediately by calling 1930 or visiting Cybercrime Portal @ www.cybercrime.gov.in.
Source:- SEBI
No comments yet.
Want to know More ?
Choose the type of company that you want to register to kick start your business.
Choose the type of license to operate your preferred telecommunication facility .
Choose the type of license for an effortless embarkment on your insurance business.
Choose suitable legal metrological certificate for your product and trade you are dealing in.
Choose the kind of IPR services to protect your intellectual property from theft and plagiarism.
Choose the type of license that you want to register for your technology driven finance company.
Choose the type of compliance to safeguard your business from non-adherence to laws which increases risks of penalties, fines and lawsuits.
Choose the type of certification to ensure customers of your high-quality products and services.
Transform your Business.