Search
Advertisement
Scammers posing as CEOs on the rise: How fraudsters' WhatsApp, email and Teams messages can steal money

Scammers posing as CEOs on the rise: How fraudsters' WhatsApp, email and Teams messages can steal money

The scam exploits workplace trust, combining convincing digital impersonation with social engineering and malware to make seemingly routine executive requests appear legitimate and trigger immediate financial transfers.

Business Today Desk
Business Today Desk
  • Noida,
  • Updated Sep 8, 2026 6:30 AM IST
Scammers posing as CEOs on the rise: How fraudsters' WhatsApp, email and Teams messages can steal moneyBoss Scam uses fake CEO identities, AI deepfakes and malware to trick finance teams into payments. (Representative image)

A cybercrime tactic dubbed the “Boss Scam” uses fake CEO and managing director identities to trick finance employees into making urgent fund transfers. The fraud can begin through email, WhatsApp, Microsoft Teams or social media platforms, with criminals relying on AI-generated deepfakes, voice cloning or malicious files to make requests appear genuine. 

Advertisement

Must Read: NHRC questions Meta’s intermediary status over AI systems, seeks asks MeitY, MIB review

In some cases, attackers can also take control of WhatsApp Web sessions after a victim opens a file. The scam highlights how a familiar name or seemingly authentic message from a senior executive can become a gateway to financial fraud, particularly when employees act without verifying requests.

How the Boss Scam works

Fraudsters impersonate CEOs or other high-ranking officials and contact their subordinates or counterparts through digital platforms. The messages contain instructions that can ultimately lead to money being transferred to accounts controlled by the scammers.

AI deepfakes make fake bosses look real

One method involves deepfake technology, including voice cloning and AI-generated video calls that impersonate CEOs or MDs. Criminals may also create fake social media groups featuring impersonated senior officials. Finance officers can then be instructed to send money to a specified mule account. In some cases, they are told to keep the transaction confidential by claiming it involves Unpublished Price Sensitive Information.

Advertisement

Must Read: Anthropic launches Fable 5.1 and Mythos 5.1 with lower costs, fewer AI restrictions

Malicious ZIP files can hijack WhatsApp

Another method involves a compressed ZIP archive containing a malicious .exe executable and .dll file. When opened on a Windows desktop or laptop, it can initiate a Trojan dropper that compromises the system and hijacks active WhatsApp Web session tokens.

The attacker can then access the finance officer’s WhatsApp account and contact employees to demand immediate payments to mule accounts. If the device is completely compromised, the scammer can also alter the contact list and save their number under the CEO or MD’s name.

How companies can protect themselves

The recommended safeguards include independently calling senior officials to verify digital requests, avoiding fund transfers based solely on social media instructions, and checking the sender before opening executable files. 

Advertisement

Companies should also log out of unused WhatsApp Web sessions. Scam incidents can be reported on 1930 or cybercrime.gov.in.

For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine

Follow us on

ABOUT THE AUTHOR

Business Today Desk
Business Today Desk

Business Today brings you the latest news, views and analysis from the world of finance, economy, markets, corporates, startups, tech, and the digital economy. You can find everything from breaking news to deep dives to immersive essays and more on a variety of subjects across all formats - online, magazine, television, data visualisation, et al.

Published on: Sep 8, 2026 6:30 AM IST