Abstract:SEBI has warned listed companies and regulated entities about the AI-driven "Boss Scam," a CEO impersonation fraud using deepfakes, voice cloning, and malware to trick finance officials into transferring funds.

India's Securities and Exchange Board (SEBI) has issued a public advisory warning listed companies and regulated entities about a rapidly emerging cyber fraud known as the “Boss Scam,” in which criminals use artificial intelligence to impersonate senior executives and trick finance staff into transferring company funds.
The statement, released on Friday, July 17, 2026, follows an alert from the Indian Cyber Crime Coordination Centre (I4C) flagging a growing trend of CEO and managing director impersonation carried out through digital communication tools.
In a typical Boss Scam, fraudsters pose as senior executives through email, WhatsApp, Microsoft Teams, or other social media platforms and instruct finance personnel to execute urgent fund transfers. The messages are crafted to appear confidential and often discourage verification by citing sensitive or unpublished information, according to SEBI.
Perpetrators are increasingly deploying advanced techniques such as deepfake voice cloning and AI-generated video calls to make the impersonation more convincing, the regulator noted.
SEBI also described a second attack method in which fraudsters send malicious ZIP files containing malware. Once opened, these files can compromise systems and hijack active WhatsApp Web session tokens, enabling criminals to send payment instructions directly from legitimate company accounts.
In a further layer of deception, attackers may alter contact details on compromised devices, replacing genuine executive phone numbers with fraudulent ones. This means a finance employee who attempts to call back and verify a suspicious instruction could unknowingly reach the fraudster.
SEBI has advised all regulated entities to independently verify any financial instruction received through digital platforms by directly contacting the concerned official through a known, trusted channel. Firms should not act solely on messages received via social media or messaging platforms and must avoid installing unverified executable files.
The regulator urged companies to immediately report any cyber fraud incidents through the national cybercrime helpline at 1930 or via the official cybercrime reporting portal.