SEBI has warned of a growing "boss scam" in which fraudsters impersonate CEOs and senior executives to coerce employees—especially finance staff—into making urgent fund transfers. Attackers use email, WhatsApp, Microsoft Teams and other social platforms, and some versions deploy malware that can hijack WhatsApp Web or compromise devices. SEBI urged regulated firms to require independent verification and to refuse payment requests based solely on social-media instructions.
SEBI Warns Of Rising 'Boss Scam' — Executives Impersonated To Steal Corporate Funds

MUMBAI, July 17 — India’s markets regulator, the Securities and Exchange Board of India (SEBI), has issued a warning about a surge in a cyber fraud known as the "boss scam," in which criminals impersonate CEOs and other senior executives to trick employees into transferring money.
How The Scam Works
According to SEBI and reports from the Indian Cyber Crime Coordination Centre, fraudsters are targeting finance teams and other staff through emails, WhatsApp, Microsoft Teams and social-media channels. Attackers pose as senior leaders and send urgent payment instructions that pressure employees to move funds immediately to bank accounts controlled by criminals, often described as "mule accounts."
Another variant sends malware-laden files to employees. If opened, these files can hijack WhatsApp Web sessions, compromise devices, or steal credentials, enabling scammers to continue impersonation and authorize further fraudulent transfers.
"The fraudster gets access to the finance officer's WhatsApp account and then contacts accounts or finance employees, instructing them to make immediate payments to specified mule bank accounts," SEBI said.
What Companies Should Do
SEBI has directed regulated entities to instruct staff not to transfer funds based solely on instructions received via social media or messaging apps. Companies should strengthen verification procedures and incident response, including:
- Require multi-factor approval for significant or unusual payments, including independent voice or video confirmation from a known executive using a verified company channel;
- Train staff to treat urgent payment requests with caution and to report suspicious messages immediately to IT and compliance teams;
- Block or sandbox unknown attachments and enforce endpoint security to detect and remove malware; and
- Maintain clear protocols for verifying changes to payment instructions or beneficiary details.
SEBI's advisory underscores the need for constant vigilance: social-media messages and instant requests should never replace formal, auditable payment controls.
(Reporting by Jayshree P. Upadhyay; editing by Maju Samuel)
Help us improve.




























