Breaking News
Loading latest updates...

WhatsApp Hacks and Voice Clones: Inside the New SEBI "Boss Scam" Warning

WhatsApp Hacks and Voice Clones: Inside the New SEBI "Boss Scam" Warning

Fake Bosses, Real Losses: SEBI Warns Against the "Boss Scam"

On Friday, July 17, 2026, the Securities and Exchange Board of India (SEBI) issued a critical warning to listed companies and regulated entities regarding a rapidly emerging cyber fraud known as the "Boss Scam".

Acting on intelligence from the Indian Cyber Crime Coordination Centre (I4C), the market regulator highlighted a dangerous surge in incidents where scammers impersonate Chief Executive Officers (CEOs), Managing Directors (MDs), and other top executives to trick employees into transferring massive amounts of corporate funds.

How the "Boss Scam" Works

Cybercriminals are specifically targeting finance executives, accountants, and junior employees who possess direct access to corporate bank accounts. Reaching out via corporate emails, WhatsApp, Microsoft Teams, and various social media platforms, the scammers pose as a top-ranking company official.

According to SEBI, the fraud generally relies on two highly sophisticated methods:

  • Deepfakes and Social Engineering: Fraudsters are weaponizing artificial intelligence to bypass human suspicion. They utilize advanced deepfake technology, including AI-generated voice cloning and fake video calls, to perfectly imitate a company leader. They create a false sense of extreme urgency, instructing the employee to make an immediate financial transfer for a highly confidential business deal, warning them not to discuss it with anyone else.

  • Malware and WhatsApp Hijacking: The second variation is a severe technological compromise. Scammers send a compressed .zip file disguised as an urgent document. If the file is opened on a Windows computer, a hidden malware payload installs and successfully hijacks the user's active WhatsApp Web session. With full access to the finance officer's messaging account, the fraudster orders subordinate employees to process payments to specified mule bank accounts. In the worst cases, attackers take complete control of the device and secretly alter the contact list—saving their own phone number under the CEO's name so that any verification phone calls go straight back to the scammer.

SEBI's Guidelines for Corporate Protection

To counter this wave of highly coordinated digital theft, SEBI has instructed organizations to strengthen their internal controls and verification procedures immediately.

The regulator advises all corporate professionals to adopt the following safety measures:

  • Never Transfer Based Solely on Text: Employees must not wire company funds based entirely on instructions received via social media, WhatsApp, or chat applications.

  • Verify Directly: Any unusual or urgent request for money transfers must be cross-checked through official, pre-established internal channels. If you receive a text from the "CEO," you must call their known, saved phone number to verify the request.

  • Secure Digital Sessions: Employees are strongly advised to log out of active WhatsApp Web sessions when they are not being used and to strictly avoid opening or installing executable files from unverified sources.