Indian Regulator Warns Financial Firms About Rising ‘Boss Scam’ Cyber Fraud

By AssetVault Recovery August 2, 2026 News
Indian Regulator Warns Financial Firms About Rising ‘Boss Scam’ Cyber Fraud

The Securities and Exchange Board of India (SEBI) has issued a warning to financial institutions over a rapidly growing cybercrime known as the “Boss Scam”, a social engineering attack in which criminals impersonate senior executives to trick employees into transferring company funds.

The regulator said the warning follows intelligence shared by the Indian Cyber Crime Coordination Centre (I4C), which has identified an increase in sophisticated impersonation attacks targeting businesses through email, messaging applications and collaboration platforms.

How the Boss Scam Works

Unlike traditional phishing campaigns, the Boss Scam relies on trust rather than technical vulnerabilities. Criminals impersonate company directors, chief executive officers or other senior executives and send urgent payment instructions to employees responsible for finance or accounting.

Messages often arrive through WhatsApp, Microsoft Teams, email or other business communication platforms. Employees may be told that a confidential acquisition, emergency supplier payment or urgent international transfer requires immediate action, leaving little time for verification.

Because the requests appear to come from trusted executives, victims may unknowingly authorise large payments before discovering the deception.

More Sophisticated Techniques Emerging

According to the regulator, cybercriminals are increasingly combining impersonation with malware attacks. In some cases, malicious files are sent to employees, allowing attackers to compromise devices or hijack communication sessions before issuing fraudulent payment requests.

Authorities say these evolving tactics demonstrate how organised cybercriminal groups continue adapting their methods to exploit both technology and human behaviour.

SEBI’s Advice to Financial Firms

The SEBI has advised regulated entities to strengthen internal payment verification procedures and ensure that employees never authorise financial transfers solely on the basis of instructions received through messaging applications or social media platforms.

Organisations are encouraged to implement independent verification procedures for significant financial transactions, particularly where payment requests involve urgency or confidentiality.

Why Businesses Remain Vulnerable

Business email compromise and executive impersonation scams continue to rank among the most financially damaging forms of cybercrime worldwide. Unlike many attacks that rely on software vulnerabilities, these schemes exploit organisational trust, employee psychology and pressure to act quickly.

As artificial intelligence improves voice cloning and deepfake technology, investigators expect executive impersonation attacks to become even more convincing, increasing the importance of internal security awareness and payment controls.

Protecting Against Executive Impersonation Fraud

Cybersecurity specialists recommend several practical measures to reduce the risk of Boss Scam attacks:

  • Verify unexpected payment requests through a separate communication channel.
  • Require dual approval for high-value financial transfers.
  • Provide regular cybersecurity awareness training for employees.
  • Be cautious of messages creating unnecessary urgency or secrecy.
  • Monitor corporate email and messaging systems for suspicious activity.

While technology continues to evolve, regulators emphasise that strong internal controls remain one of the most effective defences against social engineering attacks targeting businesses.

Official Source

The warning was issued by the Securities and Exchange Board of India (SEBI), following information received from the Indian Cyber Crime Coordination Centre (I4C).