AI & TechNews

SEBI Sounds Alarm on “Boss Scam”: AI-Powered CEO Impersonation Fraud Targets Corporate India


The Indian Cyber Crime Coordination Centre (I4C) has flagged this scam as an emerging threat to corporate finance departments across the country.

How the Scam Works

According to the advisory, fraudsters approach senior executives or their subordinates through email, WhatsApp, Microsoft Teams, and other messaging platforms, posing as a company’s top leadership. After contact is made, they issue instructions that ultimately lead finance staff to transfer company funds into accounts controlled by the criminals.

SEBI’s advisory outlines two distinct methods being used to carry out the fraud.

Deepfake impersonation. In the first approach, criminals use AI-generated voice cloning and video manipulation to convincingly imitate a CEO or MD, sometimes even appearing on video calls. In other cases, they create fake social media groups that appear to belong to senior company officials. Through these channels, finance officers are directed to move money into “mule” accounts, often with an added instruction to keep the transaction confidential, on the pretext that it involves unpublished price-sensitive information.

Malware-laced files. The second method is more technical. Fraudsters send a compressed ZIP file that, once opened, appears legitimate but actually contains a malicious executable bundled with supporting software. Investigators have found that CEOs themselves are sometimes tricked into forwarding these files to their own finance teams, lending the malware an extra layer of credibility.

If a finance employee opens and runs the file on a Windows machine, it silently installs a Trojan that hijacks the person’s active WhatsApp Web session. From there, criminals can message company employees directly from the victim’s own WhatsApp account, instructing them to send money to fraudulent accounts. In more severe cases, attackers gain full control of the device and secretly rename the fraudster’s own number in the victim’s contacts to match the CEO’s name so that future calls or messages appear to come from a trusted, familiar source.

SEBI’s Recommendations

To help companies guard against the scam, SEBI has issued the following guidance for listed companies and regulated entities:

  • Verify any payment request received over WhatsApp, email, or social media by calling the sender directly before acting on it.
  • Never authorize a fund transfer based solely on instructions received through social media platforms.
  • Avoid installing executable files unless the sender’s identity has been confirmed, including by phone, even for messages that appear to come from known contacts.
  • Log out of WhatsApp Web sessions that are not actively in use.
  • Immediately report any suspected fraud or scam attempt via the national cybercrime helpline (1930) or the portal www.cybercrime.gov.in.

Why It Matters

The advisory reflects a broader pattern regulators worldwide have flagged in recent years: the use of generative AI to make business-email-compromise and executive-impersonation scams far more convincing than earlier text-based phishing attempts. By combining voice cloning, deepfake video, and traditional malware, attackers are able to bypass the natural skepticism that might otherwise catch a suspicious request, particularly when the “boss” appears to be speaking or writing in real time.

SEBI’s decision to caution India’s listed companies and regulated entities suggests the regulator sees this as a systemic risk to corporate financial controls, not an isolated set of incidents. Companies are being urged to strengthen internal verification protocols, especially around urgent, confidential, or after-hours payment requests, as a frontline defense against a scam that is becoming harder to detect with each new wave of AI tooling.

What's your reaction?

Excited
0
Happy
0
In Love
0
Not Sure
0
Silly
0

You may also like

Leave a reply

Your email address will not be published. Required fields are marked *

More in:AI & Tech