₹1.40 Crore Gone in One WhatsApp Scam, Four Arrested in Bengaluru

The420.in Staff
9 Min Read

Karnataka Cyber Command has arrested four people in connection with a ₹1.40 crore cyber fraud in which criminals allegedly impersonated a university president on WhatsApp and persuaded an accountant to transfer money from the institution’s bank account. Police seized ₹8.50 lakh in cash and four mobile phones during the investigation.

The accused allegedly used the president’s photograph and identity to convince the accountant that the transfer request was genuine. Investigators suspect that the money was subsequently routed through multiple bank accounts.

How Did the Boss Scam Begin

The case came to light after an employee of a deemed-to-be university approached the police on September 9 and reported an unauthorised transfer from the institution’s bank account.

According to the complaint, the fraud began on September 8, when the university’s accountant, Vinay Bhushan, received a WhatsApp message from an unidentified person.

The sender used the photograph of university president Dr Chennaraj Roychand and pretended to be him.

At around 10.03 am, the fraudster contacted Bhushan and asked about the university’s bank balance. Believing the message had come from the president, the accountant responded to the request. Later, at approximately 11.34 am, the accused instructed him through WhatsApp to transfer ₹1.40 crore.

The accountant reportedly followed the instructions because he believed he was communicating with the university president. The money was subsequently transferred from the institution’s bank account.

What Is a Boss Scam?

A boss scam is a form of cyber fraud in which criminals impersonate senior executives, employers or other authority figures to persuade employees to transfer money or disclose sensitive information.

In this case, the accused allegedly used the university president’s photograph to make the WhatsApp conversation appear genuine.

The fraud relied on the accountant accepting the sender’s claimed identity without independently verifying the payment instructions.

Such scams often exploit workplace hierarchies, where employees may consider instructions from senior officials urgent or authoritative.

The Bengaluru incident illustrates how a familiar photograph and a message appearing to come from a senior official can be used to manipulate employees responsible for financial transactions.

How Did Police Trace the Accused?

Following the complaint, a case was registered at the South Division Cyber Crime Police Station under Sections 66(D) of the Information Technology Act and 318(4) of the Bharatiya Nyaya Sanhita (BNS).

Investigators examined the movement of money and the methods allegedly used to transfer the funds.

Police found that the accused had sent a ZIP file to members of the institution.

According to investigators, accessing the file through the Chrome browser and logging into WhatsApp Web allegedly allowed the accused to gain access to institutional data without the staff members’ knowledge.

Police suspect that the file was used as part of the operation to compromise accounts and obtain information.

Investigators also found that the gang had monitored the institution’s financial transactions for approximately 15 to 20 days before carrying out the fraudulent transfer.

This suggested that the accused had gathered information about the university’s financial activities before attempting to move the money.

The investigation also identified the use of foreign IP addresses in connection with the operation.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Who Has Been Arrested?

Police arrested four people following technical analysis and further investigation into the movement of the stolen money.

The accused were identified as Annayya, 25, a resident of KR Puram in Bengaluru; Rupasali Ravikumar Reddy, 26, and Ambaraya, 39, who were arrested in Hyderabad; and Syed Wajihuddin Quadri, 25, who was apprehended in connection with the money collection.

According to police, information obtained during the investigation helped officers identify the suspects and trace their alleged roles in the operation.

The accused were allegedly involved in arranging bank accounts and facilitating the movement of money after the fraudulent transfer.

Police said the operation involved multiple individuals performing different tasks, including obtaining account details, transferring funds and withdrawing cash.

Another suspect, identified as Sunny alias David, remains absconding.

Efforts are continuing to trace him.

How Was the Fraud Money Transferred?

Investigators believe the gang operated through a wider network that arranged bank accounts for receiving and transferring fraud proceeds.

According to police, Sunny alias David allegedly instructed Annayya to lure friends and acquaintances with promises of money.

These individuals were allegedly persuaded to open bank accounts and share their account details.

The accounts were then used to receive or move money connected to the fraud.

Police said Ravikumar Reddy and Ambaraya were allegedly waiting in Hyderabad to receive the transferred funds.

The money was reportedly withdrawn through cheques and handed over in cash.

Investigators suspect that this arrangement was intended to move the money through different accounts and individuals after it left the university’s bank account.

The alleged use of multiple bank accounts also complicated efforts to trace the funds.

Police are continuing to examine the financial transactions and the roles of those involved.

What Did Police Recover?

During the investigation, police recovered ₹8.50 lakh in cash and seized four mobile phones allegedly used in connection with the operation.

The seized cash was reportedly linked to another online fraud case in Aurangabad, Maharashtra.

Investigators also examined digital evidence and bank transactions to establish how the accused communicated and moved money.

The operation was conducted under the guidance of Cyber Command DGP Pranab Mohanty, with senior officers and personnel from the South Division Cyber Crime Police Station and the crime detection team involved in tracing and arresting the suspects.

Police are investigating the remaining financial trail and attempting to identify others who may have participated in the alleged fraud.

The investigation is continuing.

How Can Employees Avoid Such Scams?

Karnataka Cyber Command has advised employees to independently verify WhatsApp messages claiming to come from senior officials, particularly when they contain instructions to transfer money.

Police warned that a message carrying a senior executive’s photograph should not automatically be treated as genuine.

Employees have been advised to confirm unusual payment requests through a separate, trusted communication channel before transferring funds.

The cyber police have also warned against opening unknown ZIP files or suspicious links received through messaging platforms.

Such files may contain malicious software designed to steal information or compromise accounts.

Police further cautioned people against allowing others to use their bank accounts in exchange for commissions or other financial benefits.

Anyone who loses money in an online fraud should immediately contact the national cybercrime helpline 1930.

The420 Insight: “One WhatsApp Message Can Put an Organisation’s Funds at Risk”

The Bengaluru case shows how cybercriminals can exploit workplace authority and familiar identities to carry out financial fraud. The accused allegedly combined WhatsApp impersonation, suspicious files, monitoring of financial transactions and multiple bank accounts to execute the ₹1.40 crore transfer. For organisations, the case highlights the importance of independently verifying payment instructions, protecting institutional accounts and ensuring that no financial transfer is authorised solely on the basis of a messaging-app request.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected