Fraudsters used a fake WhatsApp identity in an Agra man's own name to steal ₹30 lakh via RTGS, mirroring a pattern now hitting Indian companies too.

Fake WhatsApp Identity Costs Agra Man ₹30 Lakh via RTGS Fraud

The420 Web Correspondent
5 Min Read

A fabricated WhatsApp account bearing Rajat Sharma’s own name was reportedly used to defraud him of ₹30 lakh, in a case that illustrates how easily digital identity can be weaponised against the very person it claims to represent. The Shahid Nagar resident’s money moved through RTGS to a Bank of India account held by Jai Durga Enterprises, and Agra’s Cyber Crime Police Station has since registered a case and begun tracing the account holder.

According to police, fraudsters created a mobile number and an accompanying WhatsApp identity carrying Sharma’s name, using it to establish contact and build sufficient trust to facilitate the transfer. The full ₹30 lakh moved in a single RTGS transaction to the business account, a detail investigators say has complicated the case, since establishing whether the account’s registered owner was directly involved or merely provided cover for the fraud requires examining KYC records and authorised signatories separately.

A Tactic Now Reaching Far Beyond Individual Victims

The Agra case sits within a rapidly escalating pattern of WhatsApp-based identity fraud that has moved well past individual targets into corporate boardrooms. In one of the most striking recent examples, former Rajya Sabha MP Naresh Gujral’s Delhi garment business lost ₹7.8 crore after fraudsters created a fake WhatsApp account using his profile photograph, convincing company officials to authorise four RTGS transfers over four days before his daughter noticed the unusual transactions and alerted him directly.

A near-identical scheme cost a Kolhapur automobile company ₹80.50 lakh after criminals impersonated its CEO’s WhatsApp identity to instruct an accounts manager to process urgent payments, funds that moved to accounts in Gujarat and Saharanpur before the fraud was discovered. The Indian Cyber Crime Coordination Centre formally named this pattern the “Boss Scam” in a June 2026 advisory, describing a racket that blends malware, social engineering and executive impersonation specifically to pressure finance staff into clearing fraudulent transfers.

Why the Deception Works So Reliably

What makes this fraud category particularly effective is that it exploits conscientiousness rather than carelessness. The employees who authorise these transfers are typically senior, trusted and accustomed to acting quickly on instructions from familiar figures, precisely the qualities a fraudster’s message is designed to leverage. A WhatsApp display name, profile photograph or even an active-seeming chat history offers no actual verification of identity, since all of these elements can be replicated using publicly available images and a freshly registered mobile number.

Investigators examining the Agra case are following a similar path to their counterparts in larger corporate cases, tracing the mobile number used to create the fake identity alongside the KYC documentation attached to the beneficiary account, to establish whether Jai Durga Enterprises’ registered account genuinely belongs to an operating business or was itself compromised or fraudulently opened for this purpose.

The One Verification Step That Consistently Works

Across nearly every documented case of this kind, the fraud unravels only once someone bypasses the digital channel entirely and confirms the request through an independent, verified line of contact, typically a direct phone call to a previously known number rather than the number the message itself originated from. Financial teams handling high-value transfers have increasingly been advised to treat this out-of-band verification as a mandatory step rather than an optional precaution, given that no technical filter can reliably distinguish a cloned WhatsApp identity from a genuine one in real time.

For individual victims like Sharma, the same principle applies at smaller scale: verifying a beneficiary’s identity and account details through a channel independent of the original message, before completing any RTGS or other high-value transfer, remains the only reliable defence against a fraud built entirely on borrowed trust rather than technical intrusion. Police in Agra continue examining banking records and the mobile number’s usage history, with no arrest reported so far in the case.

Stay Connected