

India’s capital markets regulator, the Securities and Exchange Board of India (SEBI), has cautioned regulated entities and listed companies about the growing threat of the ‘boss scam’, a cyber fraud in which criminals impersonate senior executives to steal company funds.
SEBI issued the caution on 17 July 2026 amid concerns that such fraud is becoming increasingly common in India.
Fraudsters use email, WhatsApp and forged identity documents to deceive employees in a company’s finance department. They may also use artificial intelligence (AI) to create deepfake voice messages and video calls that appear to feature the company’s senior executives.
The scam usually begins with an urgent message that appears to come from the company’s chief executive officer or managing director.
The employee may be instructed to transfer money immediately to a particular account or change the bank details of a supplier or beneficiary. The fraudster may also ask the employee to bypass the company’s established approval procedures.
Employees are often told: “This is a highly confidential transaction. Do not discuss it with anyone else in the organisation.”
Such instructions place junior employees under additional pressure. Criminals exploit three factors to carry out the fraud: urgency, respect for organisational hierarchy and trust in senior executives.
Fraudsters collect photographs, past speeches, interviews, podcasts and social media information relating to senior executives. They then use this material to create fake ‘digital clones’.
Dileep Senapathy, founder of Thiruvananthapuram-based IT consultancy Digital Live, identifies three factors that make employees vulnerable:
Manufactured urgency: Employees may be told that the company is about to lose a major deal or face legal trouble. This gives them little time to think or verify the request.
Influence of authority: Employees may accept messages appearing to come from senior executives without questioning them.
Gaps in remote working systems: Greater dependence on video calls and chat platforms while working away from the office can create opportunities for fraudsters.
AI-based systems are available to detect manipulated audio and video, but they are not foolproof, says Anil Bhatt, founder of Bengaluru-based AI product company NeuralOrbs.
Models such as AASIST and RawNet2 are used in audio anti-spoofing research to identify manipulated or artificially generated speech. Architectures such as Xception, EfficientNet and Vision Transformers are also used in video deepfake detection.
However, such systems can only provide an indication or risk score. Employees and companies must still make the final decision after independently verifying the request.
Changes in the executive’s usual speaking or writing style, unusual words, unnatural expressions or poor video quality.
Unexpected requests to change bank account details, transfer money overseas or keep a transaction secret.
Instructions to bypass normal approval procedures or complete a transaction immediately.
Verification through a second channel: When payment instructions arrive through a message or video call, contact the person through a previously saved phone number or the company’s official internal communication system.
Approval by more than one person: A single employee should not have the authority to execute large fund transfers without an additional approval.
Employee training: Staff, particularly those working in finance and accounts, should receive regular training on deepfakes, executive impersonation and emerging cyber fraud methods.
When any suspicious message is received, the transaction should be stopped immediately. The matter must also be reported without delay to the company’s cybersecurity and finance teams.