A WhatsApp message from the CEO asking an employee to urgently transfer ₹50 lakh to a new bank account may look completely genuine. The name is familiar.

HDFC Bank Warns About Executive Impersonation Fraud; Criminals May Exploit Compromised Devices and Genuine Messaging Accounts to Push Employees Into High-Value Transfers

A WhatsApp message from the CEO asking an employee to urgently transfer ₹50 lakh to a new bank account may look completely genuine. The name is familiar, the profile photograph is correct and the message may even arrive from the executive's actual account.

But that does not necessarily mean the instruction is genuine.

HDFC Bank has warned customers and businesses about the growing “Boss Scam”, in which fraudsters impersonate senior executives or compromise their digital accounts to manipulate employees into making payments or sharing sensitive information.

The fraud combines social engineering, account compromise and malware-based attacks to exploit one of the strongest forces inside an organisation — trust in senior management.

For employees handling company payments, the central lesson is simple: never process an unusual or high-value payment solely because the instruction appears to come from the boss.

What Is the Boss Scam?

The Boss Scam is a form of business impersonation fraud in which criminals pretend to be a senior executive, business owner or other trusted authority.

The fraudster may contact an employee through:

  • WhatsApp
  • Email
  • Phone calls
  • Social-media platforms
  • Other corporate messaging services

The message is generally designed to create urgency, secrecy and pressure.

The employee may be told that a payment must be made immediately for a confidential business transaction, regulatory issue, acquisition, supplier payment or emergency requirement.

The objective is to make the employee act before independently verifying the request.

The Most Dangerous Feature: The Account Could Be Genuine

In a traditional impersonation scam, criminals create a fake account using the CEO's name and photograph.

The Boss Scam can be more sophisticated.

If a senior executive's phone, email or messaging account has been compromised, criminals may be able to communicate through the genuine account.

That makes the fraud much harder to identify.

An employee may see:

  • The real executive's name
  • The correct profile picture
  • Existing conversations
  • Familiar communication history
  • The executive's usual messaging platform

Yet the person sending the new instruction could still be a criminal.

A genuine account does not automatically mean a genuine instruction.

How the Scam Can Begin

The attack may start with a seemingly harmless message.

A criminal could impersonate a regulator, senior executive or colleague and claim that an urgent compliance or security document needs to be reviewed.

The victim may then receive a compressed ZIP file or another attachment.

If the file contains malware and the recipient opens it, the attacker may gain access to the device.

From there, criminals may attempt to steal credentials, monitor communications or compromise business messaging accounts.

Why Unexpected ZIP Files Are Dangerous

Fraudsters may disguise malicious files as:

  • Compliance documents
  • Audit reports
  • Regulatory notices
  • Security reports
  • Financial statements
  • Company documents

An unexpected ZIP or executable attachment should therefore be treated with extreme caution.

HDFC Bank has advised users not to download or install unknown ZIP or executable files received from unknown sources.

Companies should also restrict unauthorised software installation and keep operating systems and security tools updated.

How Criminals Turn Access Into a Payment Fraud

Once an executive's account has been compromised, the fraudster can target employees with payment authority.

A typical message could instruct an accounts employee to transfer a large amount to a new beneficiary.

The message may deliberately include phrases such as:

  • “Urgent”
  • “Confidential”
  • “Do this immediately”
  • “Don't discuss this with anyone”
  • “I'm unavailable for a call”
  • “This needs to be completed today”

These instructions are designed to prevent the employee from slowing down and checking the request.

Why Employees Can Be Easily Manipulated

The scam exploits normal corporate hierarchy.

An employee receiving a message from a CEO may naturally assume that the instruction is authorised.

The situation becomes even more convincing when the executive appears to be contacting the employee directly.

Fraudsters exploit this trust by creating psychological pressure.

The employee may worry that questioning the CEO could cause a delay or create a problem.

That is precisely why organisations need a system in which verification is mandatory rather than optional.

Urgency Is One of the Biggest Warning Signs

An urgent request is not necessarily fraudulent.

However, an urgent request involving large amounts of money, a new beneficiary or a request to bypass normal approval procedures should immediately trigger additional verification.

Employees should never allow an urgent message to override established company controls.

A genuine emergency payment should still be capable of passing the organisation's authorised verification process.

What Should You Do If Your CEO Requests an Urgent Transfer?

The safest approach is to stop and independently verify.

Do not simply reply to the same WhatsApp conversation asking:

“Is this really you?”

If the account has been compromised, the fraudster can simply answer yes.

Instead:

Call the Executive Directly

Use a previously verified phone number from the company's records.

Do not use a number supplied in the suspicious message.

Verify Face-to-Face Where Possible

For particularly large transactions, direct confirmation can provide an additional layer of protection.

Follow the Company's Payment Process

Do not bypass maker-checker controls, approval limits or other established procedures.

Verify the Beneficiary

If the request involves a new bank account, independently confirm the account details.

Confirm the Business Purpose

Check why the payment is required, who the recipient is and whether the transaction fits the company's normal business activity.

Never Bypass Maker-Checker Controls

Companies should have multiple layers of approval for significant financial transactions.

A single employee should not be able to initiate and complete a large payment based only on an email or messaging instruction.

Effective controls can include:

  • Dual approval
  • Independent call-back verification
  • Transaction limits
  • Beneficiary verification
  • Cooling periods for newly added beneficiaries
  • Segregation of duties
  • Transaction alerts
  • Exception reporting

These controls can significantly reduce the potential impact of executive-account compromise.

New Beneficiary Requests Need Extra Scrutiny

A request to transfer money to a new bank account should always receive additional verification.

Fraudsters may claim that a vendor, supplier or business partner has changed its bank details.

Employees should independently contact the relevant party using previously verified contact information.

The change should not be confirmed through the same compromised email or messaging account that requested it.

Never Share OTPs or Banking Credentials

A Boss Scam can potentially evolve into credential theft.

Employees should never share:

  • OTPs
  • UPI PINs
  • Passwords
  • CVV
  • Card details
  • Corporate banking credentials
  • Authentication codes

A legitimate senior executive should not require an employee's personal banking credentials or OTP to authorise a normal company payment.

Warning Signs of a Boss Scam

Employees should be particularly cautious when several of the following appear together:

Warning sign Why it matters
Urgent high-value transfer Creates pressure to act quickly
New beneficiary account Common target for payment diversion
Request for secrecy Prevents independent verification
Unusual payment purpose May not match normal business activity
Request to bypass approval Attempts to defeat internal controls
Unexpected attachment Could contain malware
Request to install software Potential device compromise
Unusual communication style Possible account takeover
Refusal to speak by phone Prevents verification
Request for OTP/password Possible credential theft

The presence of one sign does not automatically establish fraud, but multiple signs should trigger an immediate verification process.

Finance and Accounts Employees Are Prime Targets

Employees handling payments are particularly attractive targets because they can initiate transactions involving substantial sums.

Companies should ensure that finance and accounts teams receive regular training on:

  • Executive impersonation
  • Phishing
  • Malware
  • Social engineering
  • Beneficiary fraud
  • Payment diversion
  • Account takeover

Employees should know exactly who to contact and what procedure to follow when they receive an unusual payment instruction.

Companies Need a ‘Pause and Verify’ Culture

Cybersecurity is not only about technology.

A company may have strong firewalls, antivirus software and authentication systems, yet a single employee can still be manipulated into authorising a fraudulent transaction.

Organisations should therefore build a culture in which employees are encouraged to pause and verify suspicious instructions — even when those instructions appear to come from senior management.

Questioning an unusual payment should be treated as good internal control, not disobedience.

What If the Payment Has Already Been Made?

If an employee realises that an unauthorised transaction has occurred, immediate action is critical.

The victim or company should contact the relevant bank immediately and report the fraudulent transaction.

In India, the National Cyber Crime Reporting Portal states that victims of cyber financial fraud can report the incident immediately by calling 1930, the national cybercrime helpline.

Complaints can also be filed through the official National Cyber Crime Reporting Portal.

National Cyber Crime Reporting Portal

Preserve Evidence After a Fraud

Victims should preserve relevant information rather than immediately deleting suspicious messages.

Important evidence may include:

  • Screenshots
  • WhatsApp or email conversations
  • Phone numbers
  • Email addresses
  • Bank account details
  • UTR or transaction numbers
  • Transaction date and time
  • Suspicious attachments
  • URLs
  • Call records
  • Payment confirmations

The cybercrime portal advises complainants to keep transaction information and supporting evidence available when filing a complaint.

Suspicious Numbers and Accounts Can Also Be Reported

The National Cyber Crime Reporting Portal provides a facility to report suspicious identifiers, including WhatsApp numbers, Telegram handles, phone numbers, email IDs, website URLs and social-media URLs.

This information can contribute to the government's repository and analysis of suspected cybercriminal identifiers.

Don't Delete the Conversation Immediately

Deleting the fraudulent conversation can remove potentially useful evidence.

Instead, preserve the communication and provide relevant information to the bank and law-enforcement authorities.

Similarly, do not open or forward suspicious attachments to colleagues.

Technology Alone Cannot Stop the Boss Scam

The growing sophistication of impersonation fraud highlights an important change in cybersecurity.

Criminals are no longer necessarily trying to convince victims that a fake website is genuine.

They may instead exploit relationships and authority.

An employee may correctly identify a suspicious link but still approve a fraudulent payment because the request appears to have come directly from the CEO.

That is why cybersecurity must combine technology with strong financial controls and employee awareness.

Three Layers of Protection

Businesses can think of protection against executive impersonation in three layers:

1. Protect the Account

Use strong passwords, multi-factor authentication, updated software and secure devices.

2. Protect the Payment Process

Use independent verification, approval limits and segregation of duties.

3. Protect the Employee

Conduct regular training and encourage employees to question unusual instructions.

The strongest defence is created when all three layers work together.

What Employees Should Remember

A Familiar Name Can Be Fake

Even if the message comes from a genuine account, the account itself could have been compromised.

Urgency Is Not Authorisation

An urgent request must still follow company payment procedures.

New Bank Details Require Verification

Never rely exclusively on the communication channel that requested the change.

Unexpected Attachments Should Be Avoided

Do not open unknown ZIP or executable files.

Never Share Credentials

Passwords, OTPs, UPI PINs and authentication codes must remain confidential.

Report Financial Fraud Immediately

Call 1930 and report the incident through the National Cyber Crime Reporting Portal as soon as possible.

A Simple Rule for Every Employee

Before approving an unusual payment, ask:

“If I had received this request from anyone other than my boss, would I consider it suspicious?”

If the answer is yes, stop.

Then independently verify the instruction.

A few minutes of verification can prevent a financial loss running into lakhs or even crores of rupees.

Market Outlook

The growing Boss Scam threat highlights a wider cybersecurity challenge for businesses: fraudsters are increasingly attacking the human layer of financial controls by exploiting trust in senior executives.

The most dangerous version is an account-takeover scenario in which criminals use a genuine executive's messaging account. In such cases, checking the profile name or photograph is not enough.

For businesses, the priority should be strengthening maker-checker systems, independent payment verification, beneficiary controls, employee awareness, device security and multi-factor authentication.

For employees, the most important rule is equally straightforward: never let urgency override verification.

If a suspicious or unauthorised financial transaction has already occurred, speed matters. The official National Cyber Crime Reporting Portal directs victims of financial cyber fraud to report it immediately through 1930 and its online reporting system.

In the digital workplace, trust should never replace verification — especially when the request involves money.

Visitors : HTML Hit Counters