Connect with us

NEWS

The Boss Scam Kept Hitting Microsoft Teams After SEBI

SEBI’s July Boss Scam note named Microsoft Teams, yet finance staff in Pune, Mumbai and Jaipur still sent crores on chat after the alert.

Published

on

Rajasthan Police say an accountant in Jaipur sent Rs 6.80 crore on 24 August after WhatsApp notes that looked like his director. SEBI had already cautioned listed companies and regulated entities on 17 July about this Boss Scam pattern on Microsoft Teams, WhatsApp and email.

The circular did not retire those apps as a way to move money. Finance staff in Pune and Mumbai had already been hit on Teams, and I4C was still texting tens of thousands of possible victims in August.

Microsoft Teams Shows Up in SEBI’s Scam Alert

The SEBI press release dated 17 July is PR No. 40/2026. It exists because the Indian Cyber Crime Coordination Centre had already flagged an emerging CEO or MD impersonation fraud, and asked the market regulator to push the warning onto listed firms.

I4C’s own advisory went out on 22 June under a longer title about regulatory impersonation, malicious Windows programs and high-value fraud. SEBI’s note arrived 25 days later and did one thing the home ministry circular had not: it named Microsoft Teams beside WhatsApp, email and other social apps as a channel for the order to pay.

The finance officer is instructed to transfer funds to a specified mule account which may/ may not be accompanied with directions to not share the transaction as it may be Unpublished Price Sensitive Information.

Securities and Exchange Board of India, Press Release No. 40/2026, Mumbai

That secrecy line is why this is a market-regulator problem and not only a cyber desk problem. Listed-company staff are trained to treat an MD’s quiet instruction as price-sensitive. Fraudsters now wrap the transfer request in the same hush.

SEBI’s own account posted the caution the day it went out.

https://x.com/SEBI_updates/status/2078084330321244378

Finance Staff Still Treat a Chat as an Order

SEBI addressed boards and “regulated entities.” The people who open the zip, join the Teams thread and hit send sit in accounts. I4C said as much when it came back in August and named chartered accountants, company directors, chief financial officers and corporate finance teams as the prime targets.

Delhi Police had already shown the human version in June. A five-member gang cloned a Mumbai managing director’s voice, called a deputy general manager, and moved about Rs 10 crore through 63 bank accounts before a Sarita Vihar branch manager stopped a Rs 9 lakh cheque and officers arrested five men.

The same desk habit shows up when the voice is real and the account is stolen. I4C’s CyberDost handle put it in one line on 2 September: criminals target accountants and finance professionals, use the boss’s name and display picture, and still work from a mobile number that is not the boss’s number. Ahmedabad Police Commissioner Anupam Singh Gahlaut recorded the same warning for that post.

A callback only works if the number in the phone is still the real one. Once a device is taken over, the saved CEO contact can be rewritten. The person who can move the money then sees a familiar name and does what the name asks.

A Fake Director Joined a Pune Teams Group

Four days before SEBI published, a 49-year-old CFO at an Italian engineering firm in Pune was working from home. Pimpri-Chinchwad police say a Microsoft Teams profile carrying the name and photo of the Italian CEO told her to pay two accounts. She sent Rs 56 lakh. A second ask the next morning, for Rs 1.5 crore, felt wrong, and she checked. The first payment had already gone.

On 31 July, 14 days after the SEBI note, South Cyber Police Station in Mumbai took a complaint from Apar Industries. The FIR says Vinayak Krishnaji Lele, senior vice president for finance, was added at 2.55 pm to a Teams group titled “Work Group.” Profiles that looked like directors Chaitanya Desai and Kushal Desai were in the chat. Senior manager Parameswaran Mahadev Ayyar, who handles banking and has been with the firm for 30 years, was told to send Rs 2.30 crore to an MB Rubber account at Bandhan Bank in West Bengal. The company reported it on 1930 on 3 August.

Bhosari MIDC police later booked a separate Pune engineering firm after an impersonator walked into the company’s Teams group with a director’s name and face and told a staffer to send Rs 30 lakh. Officers called that case notable because the order travelled on the same workplace app companies use for internal instructions.

CHAT PAYMENTS POLICE HAVE BOOKED

Date City App Amount Outcome
13 July 2026 Pune Microsoft Teams Rs 56 lakh Further Rs 1.5 crore ask stopped
31 July 2026 Mumbai Microsoft Teams Rs 2.30 crore FIR at South Cyber Police Station
August 2026 Pune (Bhosari) Microsoft Teams Rs 30 lakh FIR at Bhosari MIDC
June 2026 Ahmedabad WhatsApp Rs 1.5 crore Police say Rs 1.3 crore recovered
24 August 2026 Jaipur WhatsApp Web Rs 6.80 crore Rs 3.50 crore placed on hold

None of those files needed a spoofed email domain. The instruction arrived where staff already take orders from the people they report to.

58,000 Texts After the Market Regulator Spoke

On 7 August, the Press Information Bureau carried a fresh I4C caution to finance teams. Complaints on the National Cyber Crime Reporting Portal were rising again. Identical zip lures had shown up in Delhi, Gujarat, Maharashtra and Rajasthan. The files came as “Statement of Account.zip” (sometimes dated, such as “0714 Statement of Account.zip”), “RBI.zip” or “MCA.zip,” and some emails pretended to be from the Income Tax Department.

Once the archive runs on Windows, I4C says, the malware takes the active WhatsApp Web session and then sends the same file to the victim’s contacts and groups. The accompanying note asks the recipient to forward it to the “company finance manager for verification” and to open it on a computer. The campaign advertises the next victim’s job title.

I4C’S AUGUST COUNT

  • SMS blast: More than 58,000 potential victims were texted in the 30 days before 7 August from the header I4CMHA-G.
  • People shielded: More than 10,000 Indians were protected by geo-blocking command-and-control servers through the Sahyog Portal.
  • Who got the clues: Threat signals went to CERT-In, Microsoft Defender, Quick Heal, K7 Computing and Net Protector.
  • How it hides: NCTAU says the operators work across borders and use DLL sideloading so the payload looks like a normal library file.

Eleven days after that PIB note, Ahmedabad Cyber Crime Branch arrested Imran Ali Pyada and Inzamul Mujibar Molla, two West Bengal men accused of selling dummy SIMs, OTPs and WhatsApp accounts into the same economy. Commissioner Gahlaut said a June Boss Scam in the city had taken Rs 1.5 crore, of which Rs 1.3 crore was recovered, and that about 4,500 SIM cards sat behind a wider set of frauds.

Police put Pyada’s OTP trade at 21,000 codes for shopping and gaming over five years at Rs 100 each, which is Rs 21 lakh, plus about 900 WhatsApp activation OTPs at Rs 250 each, which is Rs 2.25 lakh. Investigators tied 251 complaints across 26 states to the numbers, and said more than 10,000 infected devices were secured in that operation. Gahlaut called the OTP shops a Cybercrime-as-a-Service layer, with malware he linked to China and Hong Kong and a call centre in Islamabad.

FROM THE FIRST I4C NOTE TO THE JAIPUR TRANSFER

  1. 22 June 2026: I4C’s NCTAU issues the Boss Scam advisory on fake RBI lures, zip archives and WhatsApp Web takeover.
  2. 13 July 2026: Pimpri-Chinchwad police record the Italian-firm Teams hit on a Pune CFO.
  3. 17 July 2026: SEBI issues PR No. 40/2026 to listed companies and regulated entities, adding Teams and deepfake calls.
  4. 31 July 2026: Apar Industries staff are pulled into a Teams “Work Group” that police say impersonated directors.
  5. 7 August 2026: I4C returns with the 58,000-SMS update and shares indicators with Microsoft Defender.
  6. 18 August 2026: Ahmedabad police announce the SIM and OTP arrests and the device takedown.
  7. 24 August 2026: A Jaipur accountant sends Rs 6.80 crore after a hijacked WhatsApp Web session.

The dates sit in a straight line. The market regulator’s letter is in the middle of that line, not at the end of it.

How the Two Boss Scam Plays Work

SEBI split the method in two. Strategy A is theatre. Strategy B is a program file. Both end with a finance officer sending money to a mule account, and both now live in the apps that replaced email after years of inbox training.

THE TWO PLAYS IN SEBI’S NOTE

  • Strategy A: Voice clones, AI video calls that look like the MD or CEO, and fake social groups in a senior’s name, often with a warning not to discuss the payment because it may be unpublished price-sensitive information.
  • Strategy B: A compressed zip that holds a malicious.exe and a.dll. I4C has watched CEOs forward that archive to finance. On a Windows PC it drops a Trojan, steals WhatsApp Web session tokens, and then writes payment orders from the real account.
  • The contact rewrite: If the attackers take the whole device, they save their own number under the CEO or MD name and keep giving orders from a second phone that the address book already trusts.

RBI, SEBI and the Ministry of Corporate Affairs do not ship security fixes or account statements as WhatsApp attachments. I4C repeated that in August. The Windows WhatsApp Web malware path is still the quiet half of Strategy B, because the session looks like the executive’s own chat rather than a stranger’s email.

Microsoft’s Own Impersonation Warning Has a Gap

Microsoft already ships tools that sound like an answer to SEBI’s Teams line. They cover a different attacker.

The product’s Scam suspected warning in Teams appears on an incoming call from outside the organisation. If you have already picked up, the app tells you to leave unless you are sure of the caller. That banner is built for a stranger. It does not fire because a profile inside the tenant is using a director’s name and photo, which is the Pune and Mumbai pattern.

Microsoft’s docs also describe Trust Indicators for external users, badges beside people who are guests, anonymous joiners or staff from another tenant. Internal colleagues carry no badge. A hijacked or lookalike director in your own Teams group therefore looks like the person you already work for.

I4C did share this campaign’s technical indicators with Microsoft Defender, so endpoint products can try to catch the zip. That is a file problem. The transfer problem is a habit: a chat from the boss is still treated as an instruction, and SEBI’s remedy is still a voice call to a number that may already have been rewritten.

Admins can still tighten the obvious switches. Block unknown.exe and.dll files from user profile folders, as I4C asked. Log out of idle WhatsApp Web sessions. Turn off external Teams chat where the business does not need it. None of those settings replaces a second person on a payment, using a number that was not pulled from the same compromised phone.

The Jaipur Transfer That Came in August

The 24 August Jaipur case is Strategy B with the contact-list trick on top. Additional DGP (Cyber Crime) Vijay Kumar Singh said attackers got onto an office computer, took the accountant’s WhatsApp Web session, rebuilt an earlier chat with the director, and then told him to RTGS Rs 6.80 crore to three accounts. No director had authorised the payments. The complaint went in on 25 August. Police placed Rs 3.50 crore on hold and arrested eight people in the first week of September, including alleged mule-account holders in Punjab and Gujarat.

Local officers also said some of the cash was being flipped into USDT. That is the same mule-and-crypto exit Ahmedabad described. The people in custody in Jaipur look like the domestic layer, not the authors of the Windows implant I4C is still trying to sink through Sahyog.

On 9 September, Tamil Nadu’s Cyber Crime Wing posted another Boss Scam alert asking staff to verify urgent payment requests before they pay. The helpline is still 1930. The portal is still www.cybercrime.gov.in.

Harry edits WinAddons, an independent news site that he owns and runs, covering Windows, Xbox, Azure, Microsoft 365, Teams, OneDrive, Outlook, the software built around them and Microsoft's business. His method comes from ten years in journalism, a reporter's years followed by an editor's, and the bulk of that decade has been spent watching Microsoft ship. His reporting starts with what Microsoft publishes: release notes and KB articles read in full, build numbers checked on an installed machine, MSRC advisories and the CVE records behind them, the Azure status history, lifecycle pages, store listings in the market they apply to, and the earnings releases and filings that carry the company's numbers. Every figure is checked against its source before publication, and a public corrections policy explains how mistakes are fixed and labelled. On security stories he does not publish exploit details before a fix is available, reporting what is affected and what to do instead. Pre-release features are labelled by channel and build, and a rumour is called a rumour. Readers can reach Harry at support@winaddons.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending