‘Boss scam’: How a Microsoft Teams message almost cost a Pune firm Rs 2 cr
Source Entity
Sushant Kulkarni

India is experiencing a surge in 'Boss Scams,' where fraudsters impersonate senior executives to trick employees into transferring corporate funds. Recent incidents include a ₹10.4 crore loss in Mumbai and a targeted attack on a Pune firm via Microsoft Teams.
The Rise of the 'Boss Scam': A New Era of Corporate Social Engineering
The corporate landscape in India is currently facing a sophisticated threat known as the "Boss Scam," a specific form of "whale phishing" where attackers impersonate high-ranking executives to manipulate subordinates into executing unauthorized financial transfers. These attacks leverage the psychological pressure of authority and the perceived urgency of executive requests to bypass standard security protocols. Recent high-profile cases, including a staggering loss of over ₹10 crore in Mumbai and a targeted attempt at a Pune-based firm, underscore a dangerous trend in cybercrime targeting the corporate hierarchy.
The Anatomy of Prolonged Manipulation
The case of Girish Amin, a deputy general manager in Mumbai, reveals the terrifying persistence of these scammers. In this instance, the attacker impersonated the executive director, Sidharth Jain, to direct Amin to transfer company funds. What makes this case particularly alarming is the volume and frequency of the fraud; Amin executed 63 separate transactions over a period of less than two weeks, totaling ₹10.40 crore. This suggests that the scammers did not just cast a wide net but actively managed the relationship with the victim, maintaining a facade of legitimacy until Amin attempted to verify the transactions through official accounting channels.
Evolution of Attack Vectors: Beyond Email
While traditional phishing often relies on email, the "Boss Scam" is evolving to utilize modern corporate collaboration tools. A significant example occurred at an Italian engineering firm in Pune, where the chief financial officer (CFO) was targeted via Microsoft Teams. By impersonating the CEO on a platform typically reserved for internal, trusted communication, the scammers successfully induced the CFO to transfer ₹56 lakh. Although a second attempt for ₹1.5 crore was thwarted by the CFO's growing suspicion, the incident highlights a critical vulnerability: the implicit trust employees place in internal messaging platforms.
Regulatory Intervention and Systemic Risk
Recognizing the scale of this threat, the Securities and Exchange Board of India (SEBI) has stepped in to caution regulated entities and listed companies. This regulatory warning was prompted by an alert from the Indian Cyber Crime Coordination Centre (I4C), indicating that these scams are becoming systemic. When high-level executives like CFOs and Deputy General Managers are targeted, it suggests that attackers are conducting deep reconnaissance on corporate structures to identify individuals with the authority to move large sums of money, posing a significant risk to corporate governance and financial stability.
The Psychology of the 'Whale Phishing' Attack
At its core, the "Boss Scam" succeeds by exploiting "authority bias." In a corporate environment, employees are conditioned to respond promptly to requests from their superiors. By creating a sense of urgency and secrecy, scammers discourage victims from seeking second opinions or following standard verification steps. In the Pune case, the CFO's immediate response to the first message demonstrates how the perceived identity of the sender can override financial caution. The gap between the initial request and the final realization of the fraud is where the most significant financial damage occurs.
Future Trends and Defensive Strategies
As cybercriminals increasingly use AI to mimic the writing styles and communication patterns of executives, the reliance on human intuition to spot "fake" messages will no longer be sufficient. To combat this, firms must implement strict "out-of-band" verification protocols, where any request for fund transfers via chat or email must be confirmed through a separate, secure channel—such as a direct phone call or a multi-factor authentication (MFA) portal. The shift from trust-based to protocol-based verification is the only way to mitigate the risk of social engineering.
Conclusion
The "Boss Scam" represents a sophisticated intersection of digital impersonation and psychological manipulation. From the ₹10.40 crore loss in Mumbai to the targeted attack in Pune, these events serve as a wake-up call for Indian businesses. With SEBI and the I4C now on high alert, companies must prioritize employee training and rigid financial controls to ensure that the trust inherent in corporate hierarchies is not weaponized against them.
Multiple Citing Sources