Posing as Company Director on WhatsApp, Fraudsters Steal ₹6.8 Crore in Jaipur ‘Boss Scam’; Two More Arrested

Rinky Rai
By Rinky Rai - A freelance journalist
4 Min Read

Rajasthan Police’s Central Cyber Crime Police Station has arrested two more persons in connection with a 6.8 crore rupee cyber fraud targeting a Jaipur-based firm, bringing the total number of arrests to six. The fraud involved cybercriminals breaching the company’s internal computer network, impersonating a director on WhatsApp, and deceiving the accounts department into transferring large sums via Real Time Gross Settlement. The latest individuals taken into custody include Sandeep Kumar, a company director from Bathinda, Punjab, whose corporate account received two crore rupees, and Baraiya Ram, an account holder based in Bhavnagar, Gujarat.

Compromised Systems and Fabricated Conversations

​According to investigators, the operation began on August 24 when the perpetrators exploited a technical vulnerability in the computer used by an accountant at the Jaipur firm. After gaining access to the machine, the fraudsters accessed the accountant’s WhatsApp Web session, blocked the actual company director’s phone number, and substituted their own contact number using the executive’s real name and display photograph.

​To eliminate suspicion, the suspects meticulously reproduced earlier WhatsApp message exchanges between the director and the accounts head. By maintaining the tone and context of past interactions, the impostor convinced the staff member that the request was legitimate. Posing as the director, the operative issued urgent directives for RTGS fund transfers, leading the employee to wire 6.8 crore rupees across three separate bank accounts without securing standard internal authorisation from any company directors. The fraud was uncovered the following day, prompting a formal complaint on August 25.

Laundering Through Corporate Mules and Cryptocurrency

​The stolen capital was rapidly dispersed through an intricate network of secondary channels to disrupt tracking efforts. Investigators noted that the money did not remain in the primary beneficiary accounts but was routed through various mule accounts, automated teller machines, signed cheques, Unified Payments Interface channels, quick-response codes, and digital wallets. A significant portion of the proceeds was subsequently converted into USDT cryptocurrency to obscure the financial trail.

​Police revealed that Sandeep Kumar had rented out his corporate bank account, opened roughly fifteen days before the operation, through arrangements made on Instagram and Telegram. He surrendered his banking kit, including his cheque book, automated teller card, SIM card, and identification papers, in exchange for a promised commission. Once two crore rupees arrived in the account, Kumar was escorted to a hotel in Reengus while the syndicate operated the funds and coordinated payout details through Telegram. The second suspect, Baraiya Ram, had sold access to his bank account, passbook, debit card, and signed cheques for a fee between 10,000 and 15,000 rupees. Police confirmed that 3.94 lakh rupees from the illicit proceeds were cleared from his account through a physical cheque withdrawal.

Multi-State Operations and Verification Protocols

​Cybercrime specialist and former police officer Professor Triveni Singh observed that the syndicate executed a sophisticated hybrid attack by combining technical unauthorized access with social engineering. By mimicking the senior executive’s communication history and profile, the criminals exploited organizational trust. Singh stressed that corporate entities must enforce strict dual-channel verification protocols, requiring employees to confirm unusual or high-value transactions via an independent communication medium before releasing funds.

​The Central Cyber Crime Police Station is currently examining call detail records, WhatsApp data, Customer Application Form identifiers, and Internet Protocol Detail Records to trace the broader syndicate. Raids are ongoing in several states to detain remaining suspects who organized the mule account infrastructure and facilitated the conversion of stolen fiat currency into digital assets.

Stay Connected