Pune (Maharashtra): A Pune-based subsidiary of an Italian engineering company has fallen victim to a sophisticated “Boss Scam” or whale phishing attack, in which cybercriminals impersonated the company’s Chief Executive Officer (CEO) through Microsoft Teams and tricked its Chief Financial Officer (CFO) into transferring ₹56 lakh. A second fraudulent request seeking ₹1.5 crore was prevented after the executive verified the instruction directly with the CEO.
According to the First Information Report (FIR), the incident occurred on July 13, when the 49-year-old CFO, who was working from home, received a Microsoft Teams message from a profile displaying the name and photograph of the company’s Italy-based CEO. The message claimed the CEO was occupied with an urgent government project and instructed her to immediately transfer ₹56 lakh to two designated bank accounts.
Believing the communication to be genuine, the CFO completed the transfer. However, the following morning she received another message directing her to urgently transfer an additional ₹1.5 crore. The repeated demand raised suspicion, prompting her to contact the CEO directly by phone. She then discovered that the Microsoft Teams account had been impersonated and immediately reported the incident to the Pimpri-Chinchwad Cyber Crime Police.
Police have launched an investigation into what cybersecurity experts describe as a whale phishing attack, also known as a CEO fraud or spear-phishing attack. Unlike mass phishing campaigns, these attacks specifically target senior executives or finance personnel responsible for authorising high-value financial transactions by impersonating trusted company leaders.
According to investigators, Pune has witnessed multiple such incidents in recent years. Since 2022, Pune City Police and Pimpri-Chinchwad Police have registered more than two dozen whale phishing cases. Earlier incidents include a ₹1 crore fraud involving the Serum Institute of India in 2022, a ₹4 crore fraud targeting a Pune real estate company in 2024, and another ₹1.95 crore CEO impersonation attack reported earlier this year.
Following an alert issued by the Indian Cyber Crime Coordination Centre (I4C), the Securities and Exchange Board of India (SEBI) has warned listed companies and regulated entities about the growing threat of “Boss Scam” or CEO/Managing Director impersonation fraud. According to the advisory, fraudsters commonly impersonate senior executives through platforms such as email, WhatsApp, Microsoft Teams, and social media to instruct finance personnel to transfer funds into mule bank accounts.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said cybercriminals are increasingly exploiting trusted enterprise communication platforms and artificial intelligence to conduct highly convincing executive impersonation attacks. He advised organisations to implement mandatory multi-level verification for all high-value financial transactions, regardless of the communication channel used. He also stressed that no payment instruction involving large sums should be executed solely on the basis of chat messages or emails without independent verification through established internal approval procedures.
Investigators are also examining emerging attack techniques identified by I4C, including AI-generated voice cloning, deepfake video calls, and malware disguised as compressed files capable of hijacking WhatsApp Web sessions and manipulating contact information to impersonate senior executives. Authorities have urged organisations to strengthen cyber awareness, deploy robust authentication mechanisms, and educate employees about executive impersonation scams as investigations into the incident continue.
