A fraudster used a Surat businessman's own photograph to impersonate him on WhatsApp, convincing his accountant to wire ₹40 lakh in a rapidly spreading corporate fraud pattern.

Inside the WhatsApp “Boss Scam” That Drained ₹40 Lakh From a Surat Firm

The420 Web Correspondent
7 Min Read

A 64-year-old textile manufacturer in Surat’s Athwalines locality did not lose ₹40 lakh to a hacker breaking into his bank account. He lost it because someone borrowed his face. Cybercriminals lifted his photograph, set it as a WhatsApp display picture, and used it to convince his own accountant that the boss was on the line.

The mechanics were almost insultingly simple. On May 20, the businessman received an unsolicited ZIP file from an unknown number, with a message asking him to check his account statements after three days. Unable to open it, he forwarded it to his accountant, who also failed to unlock the file. That single, ordinary act of delegation is what fraudsters were waiting for.

The following day, the accountant began receiving messages from a number carrying his employer’s photograph. Believing his boss was writing to him, he shared the company’s bank details on request. The impersonator, claiming to be in a meeting and unreachable by phone, instructed an RTGS transfer of ₹40 lakh. The accountant, seeing no reason to doubt a familiar face, complied.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

A Scam Built on Silence, Not Just Software

What makes this case unsettling is how little technical sophistication it needed to succeed. The fraud did not require breaching the businessman’s own WhatsApp account, only his photograph and the assumption, deeply embedded in Indian workplace culture, that instructions from a senior figure are not to be second-guessed.

The OTP authorising the transfer landed on the phone of the businessman’s son, a detail the family only pieced together after the money had already moved. It was a second son who first noticed the alert and called his father, who confirmed he had ordered no such transfer. By then, cybercrime police were registering a case under provisions relating to cheating and forgery, and the trail of the ₹40 lakh had already begun scattering across intermediary accounts.

Crucially, the same fraudster tried again the very next day, contacting a second accountant at the firm with an identical request. That attempt failed only because word of the first fraud had already spread internally, a reminder that these operations often target multiple employees within a single organisation before one of them says yes.

Part of a Fast-Growing National Pattern

The Surat case is not an isolated aberration. It belongs to a fraud typology that investigators and regulators have taken to calling the “Boss Scam”, and one that has escalated sharply through the middle of 2026. The Indian Cyber Crime Coordination Centre, the Union Home Ministry’s nodal cybercrime body, issued a formal advisory in June flagging a coordinated wave of CEO and senior-executive impersonation attempts delivered through WhatsApp, email and Microsoft Teams. The Securities and Exchange Board of India followed with its own caution to listed companies in July, treating the threat as significant enough to warrant regulatory attention rather than leaving it to individual firms to absorb the lesson.

The pattern investigators describe closely tracks what happened in Surat: a malicious archive disguised as a bank statement or regulatory notice, sent to lower the target’s guard, followed by impersonation of a senior figure demanding an urgent, unverifiable transfer. In more advanced versions documented elsewhere, the malware goes further still, hijacking an executive’s actual WhatsApp Web session on a Windows device and using the genuine account, not merely a lookalike one, to issue instructions to finance staff. Cases following this template have surfaced this year in Ahmedabad, Pune and across Rajasthan, with losses in some instances running into crores rather than lakhs.

Nationally, the numbers behind this single Surat complaint are sobering. India’s citizens reported losing more than ₹22,000 crore to cyber fraud in 2025 alone, with the national helpline 1930 logging over three crore calls through the year, an average of roughly one victim every second. Chartered accountants, company directors and finance teams have been specifically named by investigators as the demographic most exposed to this particular scheme, precisely because their job is to act quickly on instructions from above.

Verification, Not Familiarity, Is the Real Safeguard

Cybercrime expert and former IPS officer Prof. Triveni Singh, commenting on cases of this kind, has stressed that a WhatsApp message, however convincing the name and photograph attached to it, is never sufficient authentication for a high-value transaction. Fraudsters, he notes, exploit workplace hierarchy itself, betting that an employee will act first and question later when the message appears to come from a superior demanding speed.

The remedy investigators point to is neither exotic nor expensive: a callback to a verified number before any large transfer, and a mandatory second layer of approval for transactions above a set threshold, regardless of who appears to be asking. In the Surat firm’s own experience, that second layer arrived only after the damage was done, when a second accountant, forewarned by his colleague’s mistake, simply declined to share the company’s account details.

Police are now working to trace where the ₹40 lakh travelled after it left the company’s account, and whether the WhatsApp number used in Surat is linked to the wider network of syndicates that investigators believe are running similar operations against businesses across Gujarat, Maharashtra, Delhi and Rajasthan simultaneously.

Stay Connected