Business

SEBI Warns of ‘Boss Scam’ Targeting Senior Executives and Finance Teams

Mumbai: A new cyber fraud is putting companies and their finance teams on alert, with scammers increasingly pretending to be chief executive officers and other senior executives to pressure employees into transferring company funds.

The Securities and Exchange Board of India (SEBI) has issued a warning about the growing threat, commonly referred to as the “boss scam.” The regulator said it received information from the Indian Cyber Crime Coordination Centre indicating a rise in such incidents.

The scam works by exploiting something employees are naturally expected to respond to — instructions from their bosses. Fraudsters impersonate CEOs, senior management officials or other high-ranking executives and contact employees through commonly used communication platforms such as email, WhatsApp, Microsoft Teams and social media.

The messages may appear genuine and can be designed to create a sense of urgency. Employees, particularly those working in finance and accounts departments, may be told that an immediate payment or fund transfer is required. The fraudsters then provide bank account details controlled by them and attempt to convince the employee to complete the transaction without following the company’s normal verification procedures.

How the ‘boss scam’ works

In a typical case, a fraudster first identifies a company and studies its senior officials and employees. Information available through company websites, social media profiles and other online sources can help criminals understand who holds senior positions and who is responsible for handling financial transactions.

The scammer then creates the impression that the message has come directly from a CEO, director or another senior executive.

An employee could receive a message saying that an urgent payment needs to be made or that funds have to be transferred immediately for a business-related requirement. Because the request appears to come from a senior authority, an employee may feel pressured to act quickly.

SEBI has specifically cautioned that financial employees and other staff members are being targeted through multiple digital communication channels.

WhatsApp accounts can also be compromised

The fraud can become even more convincing when criminals manage to take control of an employee’s WhatsApp account.

According to SEBI, one variation involves sending malicious or malware-infected files to employees. If the recipient opens such a file, the malware may compromise the device or hijack a WhatsApp Web session.

Once criminals gain access to an employee’s WhatsApp account, they can potentially impersonate that person and contact other employees or finance officials. The messages may then instruct recipients to make urgent payments into bank accounts controlled by the fraudsters.

This creates an additional layer of deception because the victim may believe the request is coming from a familiar colleague rather than an unknown outsider.

SEBI urges companies to verify payment requests

The regulator has advised entities under its supervision to strengthen their internal safeguards and ensure employees do not transfer money simply because an instruction has arrived through a social media or messaging platform.

The warning highlights the importance of independent verification before making financial transfers. Employees should confirm unusual or urgent payment requests through an established communication channel or by directly contacting the executive who supposedly issued the instruction.

Companies may also need to ensure that employees are trained to recognise suspicious messages, unexpected attachments, unusual payment requests and attempts to bypass established approval procedures.

Why the scam is particularly dangerous

The effectiveness of the “boss scam” lies in its psychological approach. Instead of relying only on technical vulnerabilities, criminals exploit trust, authority and urgency.

An employee who receives a message appearing to come from the company’s CEO may hesitate to question the instruction, particularly when the message suggests that the matter is confidential or time-sensitive.

Cybersecurity experts have repeatedly warned that criminals are becoming increasingly sophisticated in using publicly available information to make impersonation attempts appear credible.

For companies, the financial consequences can be significant. A single unauthorised transfer can potentially result in substantial losses, while compromised employee accounts can also expose organisations to further fraud attempts.

Employees urged to slow down and verify

SEBI’s warning serves as a reminder that even a message that appears to come from a senior executive should not automatically be treated as genuine when it involves money.

Employees handling company finances should be particularly cautious when asked to make an unexpected transfer, change banking instructions, open an unfamiliar attachment or act outside the organisation’s established approval process.

Taking a few extra minutes to verify an instruction could prevent a major financial loss.

As digital communication becomes an increasingly important part of corporate operations, the latest warning underlines a simple but important lesson: when a financial request appears unusually urgent, verification should come before action.

Source: Reuters, based on information issued by SEBI and the Indian Cyber Crime Coordination Centre.

News source: Information for this article was gathered from a variety of reliable news outlets.

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *