A rice mill in Gujarat allegedly lost ₹80 lakh after a cybercriminal compromised an accountant’s phone, impersonated the business owner on WhatsApp and issued fraudulent payment instructions.
The case was reported from Sanand near Ahmedabad. The complainant, 40-year-old businessman Pradeep Dileepbhai Ramvani, operates a rice mill and has his main office in Ahmedabad.
His factory accountant, identified as Jayesh, handled important financial transactions for the business.
The fraud allegedly began on August 31 after Jayesh received a file from an unknown sender and opened it. Investigators believe his mobile phone was subsequently compromised.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Owner’s contact allegedly replaced with scammer’s number
What happened next turned an ordinary phone contact into the centre of the fraud.
According to the complaint, the attacker allegedly removed Ramvani’s genuine number from Jayesh’s contacts and replaced it with a number controlled by the fraudster.
The scammer then used Ramvani’s name and WhatsApp display photograph.
From Jayesh’s perspective, the messages therefore appeared to be coming from his employer.
The fraudster allegedly instructed him to transfer money into another bank account. Believing he was following his boss’s directions, Jayesh carried out several transactions totalling ₹80 lakh without independently confirming the request with Ramvani.
Ramvani allegedly knew nothing about the transfers.
The scam failed only when the attacker asked for another ₹30 lakh.
This time, Jayesh decided to speak directly with his employer about arranging the money.
Ramvani told him that he had never sent any such instructions.
That conversation exposed the impersonation, and a cybercrime complaint was subsequently filed.
What exactly is a ‘Boss Scam’?
The method closely resembles a cyber-fraud technique authorities call the Boss Scam, also known as CEO impersonation fraud.
The attack targets employees who have the authority to move company money.
A criminal impersonates the managing director, owner, CEO or another senior executive and creates a sense of urgency around a payment.
The message may say a confidential acquisition is taking place, a regulator needs an urgent payment or a supplier must be paid immediately.
The employee obeys because questioning a direct instruction from the boss may feel unusual.
More advanced versions add malware.
I4C has warned that attackers send malicious compressed files disguised as legitimate documents with names resembling account statements or communications from agencies such as the RBI or Ministry of Corporate Affairs. Opening them can compromise devices or communication accounts and help fraudsters impersonate senior executives.
That is why the Sanand case is especially concerning.
It was allegedly not simply a scammer copying someone’s photograph onto a new WhatsApp account. The attacker appears to have manipulated information on the employee’s device itself, making the false identity much harder to notice.
The exact technical method, however, remains under police investigation.
Similar scam cost another company ₹7.8 crore
The pattern has already produced much larger losses elsewhere in India.
Delhi Police investigated a ₹7.8 crore Boss Scam involving former MP Naresh Gujral’s company earlier this year.
According to police sources cited by The Indian Express, an employee opened a malicious ZIP file after it was forwarded as an urgent message.
The device was allegedly compromised, after which attackers altered contact details and impersonated the company owner on WhatsApp.
The accountant then transferred ₹7.8 crore through four transactions. Investigators later traced the money through a network involving 35 bank accounts across different states.
Other companies have suffered similar attacks.
Two Indian firms reportedly lost nearly ₹3.5 crore in separate cases after employees opened malicious ZIP files and criminals subsequently impersonated company executives to authorise transfers.
The repetition explains why regulators have started issuing formal warnings.
SEBI warned regulated entities in July about CEO impersonation scams involving WhatsApp, email, Microsoft Teams and other communication platforms.
The regulator advised organisations not to process financial transfers solely on instructions received over messaging or social-media channels.
A ₹30 lakh request finally triggered human verification
The most revealing part of the Sanand case may be how little technology was needed once the impersonation succeeded.
The attacker did not apparently need to hack the company’s bank account directly.
Instead, the criminal allegedly manipulated the person authorised to use it.
That distinction matters because banking security can be technically strong while internal payment procedures remain weak.
A genuine employee with legitimate access can still transfer money to a fraudster if the payment instruction appears to come from the right person.
Businesses therefore need a second layer of verification for unusual transfers.
A payment to a new beneficiary, a sudden request involving lakhs of rupees or an instruction marked confidential or urgent should trigger confirmation through a separate channel, such as calling a previously verified number or obtaining approval from another authorised officer.
In this case, one direct conversation reportedly prevented the alleged loss from increasing from ₹80 lakh to ₹1.10 crore.
Police are now examining the suspicious file, WhatsApp communications and receiving bank accounts to identify who controlled the money and whether the funds were subsequently moved through mule accounts.
What this means for you: Never approve a large payment solely because a WhatsApp profile carries your boss’s name and photograph. Businesses should require independent voice or in-person confirmation for high-value transfers, especially when bank details suddenly change.
The420 Insight: Boss scams exploit corporate hierarchy more than technical weakness. Once criminals can make an instruction look as though it came from someone senior, the employee’s trust can effectively become the authentication system — and that is exactly what attackers are learning to bypass.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics