India’s securities regulator, the Securities and Exchange Board of India (SEBI), issued a formal caution to regulated entities and listed companies on 17 July 2026 over an emerging fraud pattern known as the Boss Scam. In the scam, attackers impersonate CEOs, managing directors, and other senior officials to pressure finance and accounts staff into transferring funds. SEBI acted after the Indian Cyber Crime Coordination Centre (I4C) alerted it to a growing trend of executive impersonation carried out over email, WhatsApp, Microsoft Teams, and other digital channels.
Two attack methods
SEBI described two distinct approaches. The first is impersonation from the outside. Attackers use AI voice cloning, deepfake video calls, and fake social media groups to pose as company leadership. Finance personnel then receive urgent instructions to move money to a specified account. In some cases staff are told not to discuss the transaction because it supposedly relates to Unpublished Price Sensitive Information (UPSI). That detail deserves attention. The fraudsters are weaponising India’s insider trading rules as a silencing mechanism, turning a compliance obligation into a reason not to verify.
The second method is compromise from the inside. Attackers send a compressed .zip file containing a malicious executable and a DLL file. Opened on a Windows machine, the malware hijacks the victim’s active WhatsApp Web session tokens. The attacker then controls a genuine internal account and uses it to instruct accounts or finance employees to make immediate payments to mule bank accounts. SEBI also warned that attackers with wider device access may edit the victim’s contact list, saving their own numbers under the names of the CEO or managing director so that follow-up calls and messages appear authentic.
Why this matters for the email industry
Boss Scam is business email compromise by another name, and the pattern SEBI describes is BEC converging with collaboration tools, mobile messaging, and AI-enabled impersonation. The uncomfortable part for our industry is where email authentication sits in all this. SPF, DKIM, and DMARC remain necessary. They are no longer sufficient. In the session-hijack variant, the payment instruction comes from a real internal account. There is no spoofed domain to fail alignment. We made the same argument in our recent analysis of the attack email authentication cannot see, where device code phishing bypasses the authentication stack entirely, and in our coverage of scam mail delivered through legitimate Xero infrastructure with SPF, DKIM, and DMARC all passing. Authentication validates origin. It does not validate intent.
The pattern is not confined to India. We have previously reported a six-figure loss from email impersonation that required no hack at all, and the €5 million phishing loss at Ireland’s National Treasury Management Agency. What is new here is a securities regulator, rather than a police agency or CERT, telling listed companies that executive impersonation is now a market integrity issue.
SEBI’s guidance
SEBI advised organisations to independently verify any financial instruction received through digital channels by contacting the relevant official directly, and never to transfer funds on the basis of a digital instruction alone. It warned against installing files from unverified sources and against relying solely on communications received through messaging and social platforms. It also urged prompt reporting of incidents through India’s national cybercrime helpline and online reporting portal.
What enterprise communications teams should take from this
The practical implications extend well beyond India. High-risk approval flows need out-of-band verification on a known channel, not a reply on the channel the request arrived through. Payment steps need dual control, so no single instruction from any single account can move money. And internal identity assurance now has to span email and workplace messaging together, because attackers treat them as one surface even where security teams do not. Vendors selling executive outreach and sales engagement tooling into India should also expect buyers to ask harder questions about impersonation safeguards and workflow auditability.
The lesson SEBI is teaching Indian boardrooms applies everywhere. Urgency plus secrecy plus a payment instruction is the signature of this fraud, whichever channel carries it.







