Boss Scam on the Rise: Fake Director Messages Cost Pune Auto Dealer ₹2.2 Crore

The420.in Staff
4 Min Read

A Bavdhan-based automobile dealership allegedly lost ₹2.2 crore in a sophisticated phishing attack after cybercriminals impersonated the company’s directors and instructed an account executive to transfer funds to multiple bank accounts. The fraud, which took place between August 13 and 14, came to light when the company was closing its accounts on August 14.

The 54-year-old dealer subsequently approached the Pimpri Chinchwad cyber police and lodged a complaint against the unidentified fraudsters. The incident is being investigated as a form of business email or executive impersonation fraud commonly referred to as “whaling” or “CEO fraud”, in which criminals pose as senior company officials to manipulate employees into authorising financial transactions.

According to the complaint, the fraudsters first gained control of the dealer’s mobile messaging application account. They allegedly blocked his existing mobile number and created a new profile using another number. The new profile carried the dealer’s photograph as its display picture, making it appear to the account executive that the messages were being sent by the company’s actual director.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

The fraudsters then allegedly began communicating with the account executive through the messaging platform. They reportedly instructed her not to call the dealer or send messages to his original number. By creating the impression that the company’s senior management was communicating through the new number, the suspects allegedly prevented the employee from independently verifying the instructions.

The account executive subsequently received instructions to transfer money to bank accounts provided by the fraudsters. According to the complaint, three different bank account numbers were shared with her. Acting on the instructions, she transferred a total of ₹2.20 crore between August 13 and 14.

Investigators said the account executive did not independently verify the bank details before making the transfers because she believed the instructions had come from the company’s director. The fraudsters allegedly exploited the employee’s familiarity with the dealer and the apparent authenticity of the messaging profile to convince her that the transactions were genuine.

The fraud was discovered on the evening of August 14, when the company’s accounts were being closed. The dealer immediately realised that the transactions had not been authorised by him and contacted the cyber police. The complaint triggered an urgent effort to trace the transferred funds and prevent further movement of the money.

Cyber police managed to freeze ₹87 lakh of the allegedly defrauded amount. However, investigators found that a substantial portion of the remaining money had already been transferred from the initial recipient accounts to several other bank accounts. Police are now attempting to trace the subsequent transactions and identify the individuals operating the accounts.

The investigation is also focused on determining how the fraudsters gained access to the dealer’s messaging account and how they obtained information about the company’s internal financial processes. Investigators are expected to examine the digital devices, transaction records, bank accounts and communication trails associated with the case.

The incident highlights how impersonation-based cyber fraud can exploit routine business procedures rather than technical vulnerabilities alone. In CEO fraud cases, criminals typically rely on urgency, authority and familiarity to persuade employees to bypass normal verification procedures.

Cybersecurity experts advise businesses to independently verify payment instructions, particularly when they involve large or unusual transfers. Employees should confirm changes in bank account details through an established communication channel and avoid relying solely on messaging applications or caller identification.

Police are continuing their investigation to trace the remaining funds and identify the fraudsters involved in the ₹2.2 crore transaction trail.

Stay Connected