The hackers have found another risky way. They go into corporate offices and take out employees from the finance and accounting department of the listed companies by hacking into the company account. The hackers assume the identity of the company’s CEO, managing director, or other senior management personnel and ask for an urgent transfer of money. It works just like the scam where the criminals assume to be one’s friend or acquaintance and ask for money by sending messages through phone or WhatsApp.
The authorities have found that the “Boss Scam” is carried out by organized gangs from Southeast Asian countries like Cambodia, Myanmar, and the Philippines, who lure Indian youth. With the increasing risk of such scams, SEBI came out with a serious warning two days back regarding this cybercrime.
Acting on information received from the Indian Cyber Crime Coordination Centre (I4C), SEBI has alerted listed and corporate entities, advising them not to act on such instructions without definitive verification. India's financial sector is already grappling with various forms of financial fraud; this new development indicates that the severity of cyber fraud within the sector has reached an alarming level.
The 'Boss Scam' is essentially a sophisticated variant of Business Email Compromise (BEC). In this scam, fraudsters steal the identities of top company executives or impersonate them. They initiate contact via email, WhatsApp, Microsoft Teams, LinkedIn, or other social media platforms. Typically, they use phrases like "this is a confidential deal-transfer the funds immediately," "it is an emergency-do not use any other channel," or "the CEO has personally issued this instruction."
In many instances, they employ AI-generated voice clones or deepfake videos to enhance the credibility of calls or video calls. The targets are primarily employees with access to company bank accounts or fund transfer capabilities, such as finance executives, accountants, or junior staff. Once the funds are transferred, recovering them becomes nearly impossible. SEBI has explicitly advised verifying any fund transfer or the sharing of sensitive information through official channels-such as the company's internal systems or direct verification via phone-before proceeding. Additionally, companies are urged to strengthen internal controls, provide employee training, and adopt multi-factor verification systems.
It is worth noting that while the rapid expansion of digital payments, UPI, and online banking in recent years has enhanced convenience, it has also created new opportunities for criminals. According to the RBI's latest annual report (2025-26), banks and financial institutions reported losses totaling ₹48,021 crore across 10,114 fraud cases during the 2025-26 financial year.
This represents a 46% increase over the previous year's figure of ₹32,803 crore. Although the total number of fraud cases has declined, the aggregate financial loss has risen. Previous studies by I4C indicate that if this trend persists, annual losses from cyber fraud in India could exceed ₹1.2 lakh crore, potentially amounting to approximately 0.7% of the GDP. These figures clearly indicate that this warning from SEBI is not merely a routine alert, but a message calling for necessary vigilance across the entire corporate and financial ecosystem.
The hackers have found another risky way. They go into corporate offices and take out employees from the finance and accounting department of the listed companies by hacking into the company account. The hackers assume the identity of the company’s CEO, managing director, or other senior management personnel and ask for an urgent transfer of money. It works just like the scam where the criminals assume to be one’s friend or acquaintance and ask for money by sending messages through phone or WhatsApp.
The authorities have found that the “Boss Scam” is carried out by organized gangs from Southeast Asian countries like Cambodia, Myanmar, and the Philippines, who lure Indian youth. With the increasing risk of such scams, SEBI came out with a serious warning two days back regarding this cybercrime.
Acting on information received from the Indian Cyber Crime Coordination Centre (I4C), SEBI has alerted listed and corporate entities, advising them not to act on such instructions without definitive verification. India's financial sector is already grappling with various forms of financial fraud; this new development indicates that the severity of cyber fraud within the sector has reached an alarming level.
The 'Boss Scam' is essentially a sophisticated variant of Business Email Compromise (BEC). In this scam, fraudsters steal the identities of top company executives or impersonate them. They initiate contact via email, WhatsApp, Microsoft Teams, LinkedIn, or other social media platforms. Typically, they use phrases like "this is a confidential deal-transfer the funds immediately," "it is an emergency-do not use any other channel," or "the CEO has personally issued this instruction."
In many instances, they employ AI-generated voice clones or deepfake videos to enhance the credibility of calls or video calls. The targets are primarily employees with access to company bank accounts or fund transfer capabilities, such as finance executives, accountants, or junior staff. Once the funds are transferred, recovering them becomes nearly impossible. SEBI has explicitly advised verifying any fund transfer or the sharing of sensitive information through official channels-such as the company's internal systems or direct verification via phone-before proceeding. Additionally, companies are urged to strengthen internal controls, provide employee training, and adopt multi-factor verification systems.
It is worth noting that while the rapid expansion of digital payments, UPI, and online banking in recent years has enhanced convenience, it has also created new opportunities for criminals. According to the RBI's latest annual report (2025-26), banks and financial institutions reported losses totaling ₹48,021 crore across 10,114 fraud cases during the 2025-26 financial year.
This represents a 46% increase over the previous year's figure of ₹32,803 crore. Although the total number of fraud cases has declined, the aggregate financial loss has risen. Previous studies by I4C indicate that if this trend persists, annual losses from cyber fraud in India could exceed ₹1.2 lakh crore, potentially amounting to approximately 0.7% of the GDP. These figures clearly indicate that this warning from SEBI is not merely a routine alert, but a message calling for necessary vigilance across the entire corporate and financial ecosystem.