Case Library / Smishing (SMS Phishing) / Pune Italian Engineering Firm CFO Microsoft Teams Boss-Scam (Rs 56 Lakh Loss, 2026)

Pune Italian Engineering Firm CFO Microsoft Teams Boss-Scam (Rs 56 Lakh Loss, 2026)

A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO's name and photo demanded an urgent transfer, then caught the fraud only when a follow-up Rs 1.5 crore ask prompted her to call the real CEO.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On the morning of July 13, 2026, while working from home, the 49-year-old CFO of the Pune office of an Italian-headquartered engineering firm received a Microsoft Teams message from a profile displaying the name and photo of the company's actual Italian CEO. The message claimed the CEO was tied up with a government project and instructed her to transfer Rs 56 lakh to two bank accounts; she complied. The next morning the same impersonated profile sent a second, larger request for Rs 1.5 crore. The escalation and timing made her suspicious, and she verified by phone with the real CEO, who confirmed he had sent neither message. She then filed a complaint with the Pimpri-Chinchwad cybercrime police, who registered an FIR and opened an investigation. The incident was reported by The Indian Express, and it surfaced amid a wave of similar "boss scam" cases that prompted India's securities regulator, SEBI, to issue a nationwide advisory on July 17, 2026 warning listed companies and regulated entities about CEO-impersonation fraud conducted via WhatsApp and Microsoft Teams.

How the Attack Worked

The fraudster created or hijacked a Microsoft Teams profile carrying the name and photograph of the Italian parent company's CEO and messaged the Pune-based CFO directly while she was working from home. The message stated the CEO was occupied with a "government project" and instructed her to transfer Rs 56 lakh to two specified bank accounts, an urgency-plus-authority framing classic to CEO fraud/whale phishing. Believing the message came from her actual boss, the CFO transferred the funds without a verification call, since the request arrived on an internal-feeling, familiar corporate collaboration tool (Teams) rather than an obviously external channel like a spoofed email domain. The following morning the same impersonated profile returned with a second, larger request for Rs 1.5 crore, framed with the same urgency. This time the size and back-to-back timing of the demand raised her suspicion; she checked with her actual boss by phone, and the real CEO had no knowledge of either request, revealing the fraud. She then approached the Pimpri-Chinchwad cybercrime police, who registered an FIR and opened an investigation. No malware, deepfake audio/video, or account takeover is documented in the reporting on this specific case; the impersonation relied purely on a spoofed display name/photo plus organizational urgency and authority cues on a trusted internal messaging platform.

The Lure & the Tell

Lure: a Microsoft Teams message bearing the name and photo of the real Italian CEO, opening with a plausible-sounding excuse ("busy with a government project") to explain why he couldn't call and had to text instead, then an authoritative instruction to wire Rs 56 lakh to two accounts, using organizational hierarchy and manufactured urgency to bypass normal scrutiny. Tell that eventually broke the fraud: a second, much larger and equally urgent ask (Rs 1.5 crore) arriving the very next morning, a request pattern (escalating amount, back-to-back timing, still purely text-based with no phone or video contact) that felt off enough for the CFO to finally do what should have happened before the first transfer, call the real CEO directly, which immediately exposed the impersonation.

Outcome

Rs 56 lakh was lost on the first transfer; the Rs 1.5 crore second request was not paid. The CFO reported the fraud, an FIR was registered at the Pimpri-Chinchwad cybercrime police station, and police opened an investigation. As of the reporting reviewed (through late July 2026), no arrest, recovery of funds, or charge-sheet had been publicly reported. The case, alongside a wider spike in similar "boss scam" incidents tracked by India's Indian Cyber Crime Coordination Centre (I4C), prompted SEBI to issue a formal advisory on July 17, 2026 warning regulated entities and listed companies about the fraud pattern.

Why It Matters

This case shows CEO-impersonation fraud migrating from spoofed emails to internal collaboration platforms like Microsoft Teams, tools employees inherently trust as "inside the corporate perimeter," which lowers suspicion compared to an external email domain mismatch. It also demonstrates how cross-border corporate structures (an Italian parent, a Pune subsidiary, a foreign-national CEO the CFO may rarely speak to directly) create exactly the communication gap fraudsters exploit: a request framed as coming from a busy, distant executive is inherently harder for a local finance officer to sanity-check in real time. The near-miss on the second, larger demand illustrates the single highest-value control against this fraud family: mandatory out-of-band verification (a phone call, not a reply in the same chat thread) before executing any executive-originated payment instruction, a control that would have prevented the entire loss had it been applied to the first message. The case, and the SEBI advisory it and similar incidents triggered, mark a shift in Indian regulatory attention toward messaging-app-based (as opposed to email-based) executive impersonation fraud.

Defenses

SEBI's July 17, 2026 "Boss Scam" advisory (issued days after this and similar incidents, based on I4C data) directs regulated entities and listed companies to: never authorize fund transfers based solely on text/chat instructions from social media, WhatsApp, or Teams-style apps; independently verify any unusual or urgent payment request through a pre-established official channel (a direct phone call to the purported requester or in-person confirmation) before acting, exactly the step the CFO in this case eventually took, which stopped the loss at the first tranche; avoid opening unexpected attachments/links in messaging apps (WhatsApp Web session-hijack malware is a related vector SEBI flagged); and maintain dual-authorization / callback verification protocols for wire transfers regardless of who appears to be requesting them. Diopter's broader take: any executive-impersonation payment request arriving purely as a chat/DM, with no synchronous verification step, should trigger callback-based confirmation before funds move, and organizations should have a named, out-of-band verification channel (not a reply to the same message) for high-value transfer approvals.

Sources
  • 'Boss scam': How a Microsoft Teams message almost cost a Pune firm Rs 2 cr. The Indian Express Secondary. Primary incident narrative citing the FIR registered at Pimpri-Chinchwad cybercrime police station; names exact date (July 13, 2026), CFO's age (49), and rupee figures (Rs 56 lakh transferred, Rs 1.5 crore second demand). Verified by direct fetch: article confirms all of these details.
  • What is 'boss scam' that market regulator SEBI has warned about: How fraudsters use WhatsApp, Microsoft Teams to target company employees. The Times of India Secondary. Contextualizes the wider 'boss scam' pattern this incident belongs to, per SEBI/I4C data. Verified by direct fetch: confirms SEBI's WhatsApp/Teams impersonation warning and recommended verification controls.
  • Caution to Regulated Entities and Listed Companies - Boss Scam. Securities and Exchange Board of India (SEBI) Primary. Official government regulator advisory (July 17, 2026, PR No. 40/2026) describing the CEO/boss-scam fraud pattern and mandated verification controls; issued in the same window as this incident, based on I4C data, though it does not name this specific Pune case. Verified by direct fetch (page confirms date/PR number) plus cross-check of the full advisory text via search, which confirms the recommended controls (call seniors to verify, no fund transfers on social-media instructions alone, avoid unverified executables, log out unused WhatsApp Web sessions, report to 1930/cybercrime.gov.in).
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: the attacker likely researched the Pune subsidiary's organizational and ownership structure, consistent with using public sources such as LinkedIn, company websites, and press coverage to identify the Italian parent company's CEO by name and photograph, and to identify the CFO as the local finance decision-maker who would act on his instructions.
Countering Stage 1: Public executive identifying information (a CEO's name, role, and photograph on a company website, LinkedIn, or in press coverage) is very difficult to eliminate for any public-facing senior executive; the realistic control assumes this exposure exists and instead hardens the payment-verification process it later gets used against, per Stage 5's countermeasure.
2
Impersonation infrastructure setup: the attacker built or hijacked a Microsoft Teams profile carrying the real CEO's name and a photo plausibly pulled from public sources (company website, LinkedIn, press headshots), and staged one or more receiving 'mule' bank accounts to accept the fraudulent transfer.
Countering Stage 2: Enterprise Microsoft 365/Teams administrators can enable external-sender and unverified-account warning labels, restrict who can message internal staff under an executive's display name from outside the tenant, and monitor for newly created accounts impersonating senior officials.
3
Initial contact via a trusted internal channel: the attacker messaged the CFO directly on Microsoft Teams, a collaboration tool employees typically treat as inherently internal and lower-risk than external email, rather than using an obviously external channel.
Countering Stage 3: Train employees that a message's legitimacy depends on verified sender identity, not on which application it arrives through; internal collaboration tools like Teams should receive the same scrutiny for high-stakes financial requests as external email.
4
Pretext and urgency/authority framing: the message explained the CEO's unavailability with a plausible excuse ("busy with a government project") to justify texting instead of calling, then issued an urgent, high-authority instruction to wire funds, leveraging hierarchical deference to suppress the CFO's normal scrutiny.
Countering Stage 4: Treat an "unavailable executive plus urgent, confidential payment" narrative as a recognized fraud script (as flagged in SEBI's advisory) and train finance staff to respond to unavailability or secrecy claims with mandatory verification rather than compliance.
5
Payment instruction and fund transfer (objective completion, first tranche): the CFO transferred Rs 56 lakh to two specified bank accounts without an out-of-band verification call, completing the attacker's financial objective for the initial request.
Countering Stage 5: Require mandatory out-of-band verification, a phone call to a known, pre-established number rather than a reply in the same chat thread, before executing any executive-originated wire transfer; applied here, this single control would have prevented the entire Rs 56 lakh loss.
6
Escalation attempt and detection: the same impersonated profile returned the next morning demanding a much larger Rs 1.5 crore transfer; the size and back-to-back timing of this second ask triggered the CFO's suspicion, leading her to place an out-of-band phone call to the real CEO, which exposed the impersonation and stopped further loss.
Countering Stage 6: Maintain dual-authorization and callback-verification protocols for all high-value wire transfers regardless of the apparent requester; this is the control that actually worked in this case, since the CFO's own out-of-band call at this stage caught the fraud before the larger second payment could be sent.
Quick Facts
Victim
CFO (49, female) of the Pune office/subsidiary of an Italy-headquartered engineering company (company name not publicly disclosed in reporting)
Location
Pune (Pimpri-Chinchwad), Maharashtra, India (victim office); parent company headquartered in Italy
Date
2026-07-13
Impact
Approximately Rs 56 lakh (roughly USD 65,000-67,000 at mid-2026 exchange rates) transferred and lost across two bank accounts on the first fraudulent instruction. A second demand for Rs 1.5 crore (~USD 175,000-180,000) the following morning was not paid because the CFO grew suspicious and verified with the real CEO first; total attempted exposure across both asks was roughly Rs 2.06 crore (~USD 240,000), of which only the initial Rs 56 lakh was actually lost.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance, Manufacturing & Industrial
Related

Related Cases

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…

Incident 2026Read →

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →