SEBI Has Flagged a ‘Boss Scam’ That Uses Cloned Voices and Fake Video Calls to Move Money

The regulator’s advisory describes fraudsters impersonating chief executives to instruct finance staff to transfer funds, sometimes using AI-generated video. The message appears to come from the boss. It is urgent, it is marked confidential, and it asks for a transfer to be made quickly and without discussion. By the time

Share this story

The regulator’s advisory describes fraudsters impersonating chief executives to instruct finance staff to transfer funds, sometimes using AI-generated video.

The message appears to come from the boss. It is urgent, it is marked confidential, and it asks for a transfer to be made quickly and without discussion.

By the time anyone thinks to check, the money has usually moved.

What the Advisory Describes

On 17 July 2026, the Securities and Exchange Board of India cautioned regulated entities and listed companies about a fraud pattern it referred to as the Boss Scam. SEBI said the advisory followed an alert from the Indian Cyber Crime Coordination Centre.

According to the regulator, fraudsters impersonate chief executives, managing directors and other senior officials through email, WhatsApp, Microsoft Teams and other platforms, then instruct finance staff to transfer funds to specified bank accounts.

Two Methods That Exploit the Same Weakness

SEBI described two approaches. In the first, attackers use AI voice cloning, deepfake video calls and fake social media groups to impersonate company leadership. Instructions are often framed as confidential, in some cases described as relating to unpublished price sensitive information, which discourages the recipient from verifying.

The second method is technical. A compressed file containing a malicious executable is sent through a message. If it is opened on a Windows computer, the malware can hijack an active WhatsApp Web session, allowing the attacker to send payment instructions from an account that genuinely belongs to a colleague.

What the Regulator Has Asked Entities to Do

SEBI advised entities to log out of inactive WhatsApp Web sessions, and to report suspected cyber fraud on the national cybercrime helpline 1930 or through the National Cyber Crime Reporting Portal.

The pattern the advisory sets out has a recognisable shape. Urgency, secrecy and a payment instruction arrive together, and each element works to prevent the next question from being asked.

Verification through a separately known phone number, rather than any contact detail supplied inside the message, interrupts that sequence.

The technique is not confined to internal finance teams. In January 2026, BSE cautioned investors about a fraudulent deepfake video circulating on social media that appeared to show its managing director and chief executive offering stock recommendations, and said it was filing a police complaint.

The Wise Take

Deepfake tools have lowered the cost of a convincing impersonation, but this fraud still depends on something considerably older than the technology. It needs an organisation in which a request from the top is not questioned, and in which asking to confirm feels like an accusation. That is a process problem before it is a security problem. A standing rule that no payment instruction is acted on without a call back to a known number costs nothing, and it does not care whether the voice on the other end was ever real. The tools will keep improving. The habit of checking has to improve alongside them.

Author

  • Writer, traveller, and storyteller passionate about exploring new places, discovering different perspectives, and understanding the deeper stories behind people and experiences. At The Wise Indian, she writes stories that connect, inspire, and stay with readers.

Related Stories