Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display photo of former Rajya Sabha MP Naresh Gujral, and impersonated him to his company's finance staff to push through four RTGS transfers totaling Rs 7.68 crore before Delhi Police froze roughly Rs 4.28 crore and arrested one mule-account holder.
Reviewed by the Social Engineering Examples team.
Between June 12 and June 16, 2026, fraudsters compromised a WhatsApp account tied to Naresh Gujral's south Delhi garment/textile export business after a company director received a malicious WhatsApp ZIP-file lure and forwarded it to the company's accountant, who clicked it. Once inside, they altered the contact entry so Gujral's number was replaced with an attacker-controlled number while his real profile photo was retained, then used this spoofed identity to send urgent payment instructions to the company's finance staff (variously reported as an "employee/official" or, per Outlook India, CFO Subham Singh), impersonating Gujral. Believing the instructions genuine, the company executed four RTGS transfers totaling Rs 7.68 crore (commonly rounded in press coverage to "Rs 7.8 crore") to a set of four first-layer bank accounts (reported inconsistently across outlets as located in Maharashtra/Telangana/Andhra Pradesh, Maharashtra/Pune/Telangana, or just Maharashtra/Andhra Pradesh), from which the funds were rapidly moved through roughly 35-40 second-layer mule accounts around the country. The fraud was discovered on June 16, 2026 when a company official checked directly with Gujral's daughter and learned no such instructions had come from him; an FIR was filed the same day and Delhi Police's IFSO cyber unit took up the investigation, subsequently freezing Rs 4.28 crore (about 56% of the total; Gujral and some outlets separately described the recovery, less precisely, as "over 70%") and arresting one mule-account holder on June 22-23.
Police sources described the mechanics as follows: fraudsters first sent a malicious WhatsApp message carrying a link to a ZIP file, using a lure along the lines of "Your company account is going to be closed, please verify your account." A company director received and, perceiving it as urgent, forwarded it to the company's accountant, who clicked the link and had their device/WhatsApp session compromised as a result. Using the compromised access, the fraudsters altered the contact entry in the company phone(s) so that Naresh Gujral's registered number was swapped for a number the fraudsters controlled; critically, they retained Gujral's real profile photo (display picture), so messages from the fraudulent number still appeared on-screen as coming from "Naresh Gujral." From this spoofed identity, the fraudsters sent urgent instructions to the company's finance staff (reported by Outlook India as CFO Subham Singh; other outlets describe the recipient more generically as an "employee" or "official" with financial/RTGS authority) to execute payments, invoking Gujral's real authority as the boss. The company complied and executed four separate RTGS transfers totaling Rs 7.68 crore to four "first-layer" mule accounts, from which the money was then rapidly layered through roughly 35-40 "second-layer" mule accounts nationwide to obscure the trail before it could be frozen. Note: the states hosting the four first-layer accounts are reported inconsistently across outlets. Indian Express's June 23 mechanics piece and the420.in both specify Maharashtra, Telangana, and Andhra Pradesh (Indian Express detailing "two in Maharashtra and one each in Telangana and Andhra Pradesh"); Times of India's June 22 arrest piece instead lists "Maharashtra, Pune and Telangana" (Pune being a city within Maharashtra, suggesting an editing/sourcing error rather than a fourth distinct state); and Business Today's PTI-sourced piece names only Maharashtra and Andhra Pradesh. This detail is unresolved in the underlying press corpus and is presented here as reported, not as a settled fact.
The lure combined two layers: first, a plausible pretext ZIP/link message ("your company account is going to be closed, please verify") sent via WhatsApp to a company director who, perceiving urgency, forwarded it to the accountant, whose click compromised a device/session; second, once inside, the fraudsters exploited WhatsApp's contact-name/photo model, in which a contact entry is just a locally-stored label over a phone number and the display picture is fetched independently, so they could swap in a new number while keeping Gujral's real photo attached, making messages from an attacker-controlled number look, to the eye, exactly like messages from the real boss. The "tell" that exposed it: the urgency and specificity of the RTGS instructions prompted a company official to seek independent confirmation, not by replying on WhatsApp but by checking with Gujral's daughter through a separate channel, who confirmed her father had issued no such instructions, at which point the scheme unraveled and the FIR was filed the same day (June 16, 2026).
An FIR was registered on June 16, 2026 and the case was assigned to Delhi Police's IFSO (Intelligence Fusion and Strategic Operations) cyber unit. Investigators traced the money through four first-layer accounts and roughly 35-40 second-layer mule accounts nationwide, and IFSO commissioner Vinit Kumar publicly confirmed placing a lien/freeze on Rs 4.28 crore of the stolen Rs 7.68 crore across various banks. On June 22-23, 2026, police arrested a 40-year-old mule-account holder, identified as Navneet, in Punjab (Indian Express specifies Amritsar), alleging he had let his bank account be used to receive and forward the defrauded funds in exchange for a commission. Indian Express reports this as roughly Rs 5 lakh at a 5% cut and describes him as a small-time businessman; the Times of India's June 22 arrest piece instead reports that roughly Rs 15 lakh from the defrauded amount was routed through his account and describes him as working for a private company, an inconsistency in the underlying coverage that is presented here as reported. As of the most recent reporting, the investigation into the broader mule network and any additional arrests was ongoing. No case-specific primary source (a published FIR document, chargesheet, court filing, or standalone police press release) could be located publicly. All police-attributed detail in this record, including the Rs 4.28 crore lien figure and Vinit Kumar's on-record quote, comes from statements to reporters embedded within secondary news coverage, not from an independently verifiable police document.
This case is a clear illustration of "boss scam" / CEO-fraud logic migrating from spoofed email (classic BEC) onto messaging apps, where the visual trust cue of a contact's photo and chat history can be manipulated independently of the actual phone number behind it. It shows that (a) malware delivery via a simple ZIP/link lure on a trusted consumer app remains highly effective against business finance workflows, even when the initial click comes via an internal forward from a trusted colleague rather than directly from the attacker, (b) impersonating a real, socially prominent authority figure (a former MP, tied to a former PM) supercharges compliance even among experienced staff, and (c) large sums can be laundered through many-layered mule-account networks within days, meaning speed of detection and freeze requests is the primary lever for recovery: the bank-confirmed ~56% (not the victim-quoted 70%) recovery rate here reflects how much value is typically un-recoverable once funds clear multiple layers. For organizations, it reinforces that no messaging-app identity marker (photo, display name, chat history) is a substitute for out-of-band verification on payment instructions.
Reported defensive/response measures: (1) the fraud was caught only because a company official independently verified the unusual urgent-transfer instruction with Gujral's daughter rather than relying solely on the WhatsApp message, the verification step that should have happened before, not after, the transfers; (2) Delhi Police IFSO's rapid bank-side lien/freeze action recovered a portion of funds by acting on the money trail within days; (3) the case illustrates the need for out-of-band verification (a phone call to a known number, not a reply on the same compromised channel) for any payment instruction, especially one carrying urgency/authority framing from a "boss": IFSO's deputy commissioner was quoted publicly making this exact recommendation; (4) organizations should treat WhatsApp (or any single messaging channel) as insufficient authentication for high-value payment approval, and should never open unsolicited ZIP/executable attachments even when apparently sent by a known contact or forwarded internally by a trusted colleague; (5) enabling WhatsApp two-step verification and monitoring for unexpected "linked device" or contact-list changes can prevent the account-level compromise that enabled the impersonation.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…