Case Library / Vishing (Voice Phishing) / Naresh Gujral WhatsApp CEO-Impersonation Fraud (2026)

Naresh Gujral WhatsApp CEO-Impersonation Fraud (2026)

Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display photo of former Rajya Sabha MP Naresh Gujral, and impersonated him to his company's finance staff to push through four RTGS transfers totaling Rs 7.68 crore before Delhi Police froze roughly Rs 4.28 crore and arrested one mule-account holder.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between June 12 and June 16, 2026, fraudsters compromised a WhatsApp account tied to Naresh Gujral's south Delhi garment/textile export business after a company director received a malicious WhatsApp ZIP-file lure and forwarded it to the company's accountant, who clicked it. Once inside, they altered the contact entry so Gujral's number was replaced with an attacker-controlled number while his real profile photo was retained, then used this spoofed identity to send urgent payment instructions to the company's finance staff (variously reported as an "employee/official" or, per Outlook India, CFO Subham Singh), impersonating Gujral. Believing the instructions genuine, the company executed four RTGS transfers totaling Rs 7.68 crore (commonly rounded in press coverage to "Rs 7.8 crore") to a set of four first-layer bank accounts (reported inconsistently across outlets as located in Maharashtra/Telangana/Andhra Pradesh, Maharashtra/Pune/Telangana, or just Maharashtra/Andhra Pradesh), from which the funds were rapidly moved through roughly 35-40 second-layer mule accounts around the country. The fraud was discovered on June 16, 2026 when a company official checked directly with Gujral's daughter and learned no such instructions had come from him; an FIR was filed the same day and Delhi Police's IFSO cyber unit took up the investigation, subsequently freezing Rs 4.28 crore (about 56% of the total; Gujral and some outlets separately described the recovery, less precisely, as "over 70%") and arresting one mule-account holder on June 22-23.

How the Attack Worked

Police sources described the mechanics as follows: fraudsters first sent a malicious WhatsApp message carrying a link to a ZIP file, using a lure along the lines of "Your company account is going to be closed, please verify your account." A company director received and, perceiving it as urgent, forwarded it to the company's accountant, who clicked the link and had their device/WhatsApp session compromised as a result. Using the compromised access, the fraudsters altered the contact entry in the company phone(s) so that Naresh Gujral's registered number was swapped for a number the fraudsters controlled; critically, they retained Gujral's real profile photo (display picture), so messages from the fraudulent number still appeared on-screen as coming from "Naresh Gujral." From this spoofed identity, the fraudsters sent urgent instructions to the company's finance staff (reported by Outlook India as CFO Subham Singh; other outlets describe the recipient more generically as an "employee" or "official" with financial/RTGS authority) to execute payments, invoking Gujral's real authority as the boss. The company complied and executed four separate RTGS transfers totaling Rs 7.68 crore to four "first-layer" mule accounts, from which the money was then rapidly layered through roughly 35-40 "second-layer" mule accounts nationwide to obscure the trail before it could be frozen. Note: the states hosting the four first-layer accounts are reported inconsistently across outlets. Indian Express's June 23 mechanics piece and the420.in both specify Maharashtra, Telangana, and Andhra Pradesh (Indian Express detailing "two in Maharashtra and one each in Telangana and Andhra Pradesh"); Times of India's June 22 arrest piece instead lists "Maharashtra, Pune and Telangana" (Pune being a city within Maharashtra, suggesting an editing/sourcing error rather than a fourth distinct state); and Business Today's PTI-sourced piece names only Maharashtra and Andhra Pradesh. This detail is unresolved in the underlying press corpus and is presented here as reported, not as a settled fact.

The Lure & the Tell

The lure combined two layers: first, a plausible pretext ZIP/link message ("your company account is going to be closed, please verify") sent via WhatsApp to a company director who, perceiving urgency, forwarded it to the accountant, whose click compromised a device/session; second, once inside, the fraudsters exploited WhatsApp's contact-name/photo model, in which a contact entry is just a locally-stored label over a phone number and the display picture is fetched independently, so they could swap in a new number while keeping Gujral's real photo attached, making messages from an attacker-controlled number look, to the eye, exactly like messages from the real boss. The "tell" that exposed it: the urgency and specificity of the RTGS instructions prompted a company official to seek independent confirmation, not by replying on WhatsApp but by checking with Gujral's daughter through a separate channel, who confirmed her father had issued no such instructions, at which point the scheme unraveled and the FIR was filed the same day (June 16, 2026).

Outcome

An FIR was registered on June 16, 2026 and the case was assigned to Delhi Police's IFSO (Intelligence Fusion and Strategic Operations) cyber unit. Investigators traced the money through four first-layer accounts and roughly 35-40 second-layer mule accounts nationwide, and IFSO commissioner Vinit Kumar publicly confirmed placing a lien/freeze on Rs 4.28 crore of the stolen Rs 7.68 crore across various banks. On June 22-23, 2026, police arrested a 40-year-old mule-account holder, identified as Navneet, in Punjab (Indian Express specifies Amritsar), alleging he had let his bank account be used to receive and forward the defrauded funds in exchange for a commission. Indian Express reports this as roughly Rs 5 lakh at a 5% cut and describes him as a small-time businessman; the Times of India's June 22 arrest piece instead reports that roughly Rs 15 lakh from the defrauded amount was routed through his account and describes him as working for a private company, an inconsistency in the underlying coverage that is presented here as reported. As of the most recent reporting, the investigation into the broader mule network and any additional arrests was ongoing. No case-specific primary source (a published FIR document, chargesheet, court filing, or standalone police press release) could be located publicly. All police-attributed detail in this record, including the Rs 4.28 crore lien figure and Vinit Kumar's on-record quote, comes from statements to reporters embedded within secondary news coverage, not from an independently verifiable police document.

Why It Matters

This case is a clear illustration of "boss scam" / CEO-fraud logic migrating from spoofed email (classic BEC) onto messaging apps, where the visual trust cue of a contact's photo and chat history can be manipulated independently of the actual phone number behind it. It shows that (a) malware delivery via a simple ZIP/link lure on a trusted consumer app remains highly effective against business finance workflows, even when the initial click comes via an internal forward from a trusted colleague rather than directly from the attacker, (b) impersonating a real, socially prominent authority figure (a former MP, tied to a former PM) supercharges compliance even among experienced staff, and (c) large sums can be laundered through many-layered mule-account networks within days, meaning speed of detection and freeze requests is the primary lever for recovery: the bank-confirmed ~56% (not the victim-quoted 70%) recovery rate here reflects how much value is typically un-recoverable once funds clear multiple layers. For organizations, it reinforces that no messaging-app identity marker (photo, display name, chat history) is a substitute for out-of-band verification on payment instructions.

Defenses

Reported defensive/response measures: (1) the fraud was caught only because a company official independently verified the unusual urgent-transfer instruction with Gujral's daughter rather than relying solely on the WhatsApp message, the verification step that should have happened before, not after, the transfers; (2) Delhi Police IFSO's rapid bank-side lien/freeze action recovered a portion of funds by acting on the money trail within days; (3) the case illustrates the need for out-of-band verification (a phone call to a known number, not a reply on the same compromised channel) for any payment instruction, especially one carrying urgency/authority framing from a "boss": IFSO's deputy commissioner was quoted publicly making this exact recommendation; (4) organizations should treat WhatsApp (or any single messaging channel) as insufficient authentication for high-value payment approval, and should never open unsolicited ZIP/executable attachments even when apparently sent by a known contact or forwarded internally by a trusted colleague; (5) enabling WhatsApp two-step verification and monitoring for unexpected "linked device" or contact-list changes can prevent the account-level compromise that enabled the impersonation.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target profiling: Consistent with how "boss scam" operators are typically described in Indian cybercrime reporting, the attackers likely identified Naresh Gujral, a former Rajya Sabha MP and son of a former Prime Minister who also runs a family textiles export business, as a high-value impersonation target using publicly available biographical and corporate information, then built enough of a profile of his real name, photo, and business role to make a spoofed identity convincing to his own finance staff.
Countering Stage 1: Public biographical and corporate exposure for a socially prominent business owner is very hard to eliminate; the realistic control assumes attackers already know who the boss is and instead hardens the internal process that authority-framed instructions must pass through, rather than trying to hide who the boss is.
2
Lure crafting and delivery: The fraudsters sent a WhatsApp message carrying a link to a malicious ZIP file, using a generic but urgent pretext ("your company account is going to be closed, please verify"), a low-cost, broadly reusable social-engineering template rather than a bespoke exploit built for this target.
Countering Stage 2: Treating unsolicited ZIP/archive links on any messaging app, including WhatsApp, as inherently suspicious, and deploying mobile threat-detection or link-scanning tools on corporate and BYOD devices used for business communication, reduces the odds the lure ever executes.
3
Initial device compromise via internal forwarding: A company director received the lure and, perceiving it as urgent, forwarded it to the company's accountant, whose click compromised the device or WhatsApp session, showing how an internal forward from a trusted colleague can bypass the caution a person might apply to a message from a stranger.
Countering Stage 3: Security-awareness training that explicitly covers internal forwarding, treating a link or attachment forwarded by a trusted colleague as no more verified than one from a stranger, would have given the accountant a reason to pause before clicking.
4
Contact-identity spoofing: Using the compromised access, the attackers altered the contact entry so Gujral's real number was replaced with an attacker-controlled number while his genuine profile photo was retained, exploiting WhatsApp's decoupling of a saved contact name and photo from the underlying phone number behind it.
Countering Stage 4: Enabling WhatsApp two-step verification and alerting on linked-device or contact-list changes raises the difficulty of the silent account manipulation that let the fraudsters retain Gujral's photo while swapping in their own number.
5
Impersonation and social engineering of finance staff: From the spoofed identity, the attackers sent urgent RTGS payment instructions to the company's finance staff (reported as CFO Subham Singh, per Outlook India), invoking Gujral's real authority and framing the requests as time-critical business needs.
Countering Stage 5: Mandatory out-of-band verification for any payment instruction carrying urgency or executive-authority framing, a phone call to a known number rather than a reply on the same channel, directly targets the impersonation step and is exactly what ultimately exposed this fraud, just after the money moved instead of before.
6
Fraudulent execution: Believing the instructions genuine, finance staff executed four separate RTGS transfers totaling Rs 7.68 crore to four first-layer mule accounts, with the bank flagging the transfers as unusually large only after they were already underway.
Countering Stage 6: Dual-control or maker-checker approval and bank-side transaction-monitoring thresholds for large or back-to-back RTGS transfers can stop or delay execution long enough for a verification call to happen; the bank's own flagging of these transfers shows the control exists but arrived after the fact rather than before.
7
Multi-layer laundering and payout: The stolen funds were rapidly dispersed from the four first-layer accounts through roughly 35-40 second-layer mule accounts nationwide, a layering pattern typical of commercial mule-account networks, to break the money trail and convert the funds into a form the fraudsters could withdraw before banks or police could act.
Countering Stage 7: Speed of detection and reporting is the primary lever once funds are transferred; rapid escalation to a bank's fraud desk and to a dedicated cyber-fraud unit like Delhi Police's IFSO, as happened here within hours of discovery, is what allowed roughly 56% of the stolen amount to be frozen before it cleared additional laundering layers.
Quick Facts
Victim
Naresh Gujral (former Rajya Sabha MP, son of former Indian Prime Minister I.K. Gujral) and his family-run south Delhi textiles/garment export company
Location
New Delhi, India (fraud); mule-account arrest made in/near Amritsar, Punjab
Date
2026-06-12 to 2026-06-16 (fraud window); FIR filed 2026-06-16; arrest 2026-06-22/23
Impact
Rs 7.68 crore (~US $920,000 at prevailing rates) stolen via four RTGS transfers; widely rounded in headlines to "Rs 7.8 crore." Delhi Police later reported Rs 4.28 crore marked as lien/frozen across various banks (roughly 56% of the total). Gujral himself and several outlets (PTI/Business Today, Times of India, Outlook) quoted him and police sources describing the recovery as "more than 70 per cent" or "almost 70%"; that 70% figure does not reconcile with the quoted Rs 4.28 crore lien amount against Rs 7.68 crore stolen (which is ~55.7%, rounding to 56%), so the 70% figure should be treated as an optimistic/approximate figure from the victim and unnamed police sources rather than a reconciled final recovery rate. The precise, bank-confirmed lien figure (Rs 4.28 crore / ~56%) is the better-sourced number, attributed on record to IFSO commissioner Vinit Kumar.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Manufacturing & Industrial
Threat Actor
Organized Crime
Related

Related Cases

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…

Incident 2026Read →

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →