Watch Out for the ‘Boss Scam’: How Corporate Workers Are Being Tricked into Draining Office Accounts
Summarized by AI; it may make mistakes. Check important info
Summarized by AI; it may make mistakes. Check important info

It starts with a simple, high-priority WhatsApp message or a sudden video call. The profile picture shows your company’s Managing Director or Chief Executive Officer. The voice sounds exactly like theirs. The instruction is direct and intense: “We are closing a highly confidential corporate deal right now. Transfer ₹50 lakh to this vendor account immediately, and do not discuss this with anyone in the office.”
For many junior employees and accounts professionals across India, this exact scenario has turned into a workplace nightmare.
The Securities and Exchange Board of India (SEBI), acting on an urgent national alert from the Indian Cyber Crime Coordination Centre (I4C), has issued a strict advisory to all listed companies and financial institutions. A highly dangerous corporate fraud—dubbed the ‘Boss Scam’—is aggressively targeting Indian corporate offices, siphoning off crores of rupees in minutes.
The Modus Operandi: How the Trap is Sprung
According to intelligence gathered by the cybercrime cell, fraudsters are no longer relying on simple, poorly written phishing emails. Instead, they are executing precision strikes using two highly sophisticated methods:
Method 1: The Digital Clone and 'Secret' Deals
In this approach, criminals use advanced technology to copy the actual voice of a company’s top executive. They create fake WhatsApp groups or orchestrate video calls that mimic the boss.
To prevent the employee from double-checking with other senior managers, the fake boss explicitly warns them that the fund transfer involves Unpublished Price Sensitive Information (UPSI). By claiming the deal is a legal secret, the fraudsters weaponise corporate authority, forcing the employee to bypass regular accounting checks out of fear or obedience.
Method 2: The WhatsApp Web Hijack
This method begins with a malicious, compressed file sent to an executive's computer under the guise of an urgent regulatory compliance document from authorities like the Reserve Bank of India (RBI).
Once the file is opened on a Windows desktop, a hidden software package immediately installs itself. This software silently steals the active session data of WhatsApp Web running on that computer.
With full control over the executive's real messaging account, the fraudster text-chats with the finance team, ordering immediate payments to dummy bank accounts. In severe cases, hackers take full control of the device and secretly swap out numbers in the contact list—saving the criminal's phone number under the name "CEO"—so future text messages look entirely legitimate to the unsuspecting employee.
The Financial Damage
Industry experts warn that once a transfer is made through these scams, the money is rapidly dispersed across hundreds of distributed accounts, making recovery nearly impossible. Unlike generic internet scams that target the public with small amounts, a single executive impersonation strike can drain a company's monthly budget or crucial operational funds in under ten minutes.
The Mandatory Safety Steps for Office Employees
To shield Indian businesses from these targeted attacks, regulators have urged all corporate professionals to immediately adopt a strict safety checklist:
- The Golden Rule of Verbal Double-Checking: Never authorize or initiate any urgent financial transaction based solely on a text message, WhatsApp chat, or email. Employees must pick up a regular telephone and make a direct voice call to their senior to verbally confirm the request first.
- Log Out of Web Apps: Always actively log out of WhatsApp Web, Microsoft Teams, and other office communication tools on your desktop computer as soon as you are done using them. Do not leave sessions active in the background.
- Ban Unverified Attachments: Never download or extract compressed archive files received from unverified sources, even if they appear to come from an official body or a known colleague.
- Report Instantly: If you spot an attempted executive scam, report the incident immediately by dialling the national cybercrime helpline at 1930 or logging a formal complaint at the official portal (cybercrime.gov.in).