The Securities and Exchange Board of India (SEBI) has formally cautioned listed companies and other regulated entities about a fast-growing cyber fraud that impersonates chief executive officers (CEOs) and other senior officials to trick finance teams into moving money.
The advisory, issued on 17 July 2026, comes close on the heels of an article Moneylife carried on 26 June 2026, which had already flagged this very fraud and warned readers about the dangers of unsolicited ZIP files landing on WhatsApp.
According to SEBI, the trigger for the advisory was an alert from the Indian Cyber Crime Coordination Centre (I4C) which had observed a rising pattern of CEO or managing director (MD) impersonation fraud aimed at organisations through email, WhatsApp, Microsoft Teams and other social media platforms.
The regulator explained that fraudsters typically impersonate senior executives and either send messages or place calls directing subordinates to urgently transfer funds to specified bank accounts. In several instances, the criminals have gone a step further, deploying artificial intelligence (AI) tools such as voice cloning and deepfake video calls to make the impersonation more convincing.
SEBI also flagged a second, more technical route that closely mirrors what Moneylife had described in its earlier piece: fraudsters sending a compressed ZIP file that carries malicious software. Once this file is opened on a Windows device, the malware hijacks any active WhatsApp Web session, letting the fraudsters step into the victim's genuine account and issue payment instructions directly to finance or accounts staff.
The regulator's advisory adds a detail worth underlining: in some cases, once a device is compromised, cybercriminals go on to alter its saved contact list, storing their own number under the name of the CEO or MD. Since the victim's screen then displays a familiar name rather than an unfamiliar number, the deception becomes harder to catch — a trick that our 26 June 2026 story had also documented in detail, based on cases probed by I4C.
To limit exposure, SEBI has asked listed companies and regulated entities to independently verify any fund-transfer request that arrives over WhatsApp, email or other social media, ideally by placing a direct call to the concerned senior official rather than relying on the message alone. It further advised organisations against approving transfers purely on the strength of instructions received through social media platforms, and against installing executable (.exe) files without first confirming the sender's identity.
SEBI has additionally urged entities to log out of inactive WhatsApp Web sessions and to report any cyber fraud immediately, either by calling the national cybercrime helpline at 1930 or through the Cyber Crime portal.
The advisory effectively puts regulatory weight behind warnings that Moneylife had already sounded a few weeks earlier. Our 26 June 2026 report on the 'Boss Scam 2.0' had traced how one such fraud cost a company ₹7.8 crore, walked through the five-stage playbook cybercriminals use — from manufacturing panic to moving money through mule accounts — and had also flagged a parallel warning from the Indian Computer Emergency Response Team (CERT-In) about fake invoices carrying malware through VBScript (.vbs) files. Readers looking for the fuller breakdown, including the red flags to watch for and the safeguards companies should put in place, can revisit that story.
With SEBI now formally weighing in, the message for corporate India is unambiguous: no urgent payment instruction, however senior its apparent source, should be acted upon without an independent check outside the same communication channel.
It is widely assumed that India will sustain a 7%-8% annual growth rate in gross domestic product (GDP) for the next few decades and will soon reach the upper-middle income category and even the high-income country category. On the...
India has never invested more heavily in infrastructure than in the past decade. Highways, expressways, airports, tunnels, bridges and ports have been built at record speed. These have been showcased through drone footage, glossy...
Nearly 19,000 files linked to India's largest nuclear power project at Kudankulam have surfaced on the dark web following a ransomware attack on systems belonging to Reliance Infrastructure Ltd, one of the project's contractors,...
Supreme Court Bar Association (SCBA) president and senior counsel Dr Vikas Singh has appealed to education reformer and environmentalist Sonam Wangchuk to end his hunger strike over concerns relating to the national...
Fiercely independent and pro-consumer information on personal finance.
1-year online access to the magazine articles published during the subscription period.
Access is given for all articles published during the week (starting Monday) your subscription starts. For example, if you subscribe on Wednesday, you will have access to articles uploaded from Monday of that week.
This means access to other articles (outside the subscription period) are not included.
Articles outside the subscription period can be bought separately for a small price per article.
Fiercely independent and pro-consumer information on personal finance.
30-day online access to the magazine articles published during the subscription period.
Access is given for all articles published during the week (starting Monday) your subscription starts. For example, if you subscribe on Wednesday, you will have access to articles uploaded from Monday of that week.
This means access to other articles (outside the subscription period) are not included.
Articles outside the subscription period can be bought separately for a small price per article.
Fiercely independent and pro-consumer information on personal finance.
Complete access to Moneylife archives since inception ( till the date of your subscription )