A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO's name and photo demanded an urgent transfer, then caught the fraud only when a follow-up Rs 1.5 crore ask prompted her to call the real CEO.
Reviewed by the Social Engineering Examples team.
On the morning of July 13, 2026, while working from home, the 49-year-old CFO of the Pune office of an Italian-headquartered engineering firm received a Microsoft Teams message from a profile displaying the name and photo of the company's actual Italian CEO. The message claimed the CEO was tied up with a government project and instructed her to transfer Rs 56 lakh to two bank accounts; she complied. The next morning the same impersonated profile sent a second, larger request for Rs 1.5 crore. The escalation and timing made her suspicious, and she verified by phone with the real CEO, who confirmed he had sent neither message. She then filed a complaint with the Pimpri-Chinchwad cybercrime police, who registered an FIR and opened an investigation. The incident was reported by The Indian Express, and it surfaced amid a wave of similar "boss scam" cases that prompted India's securities regulator, SEBI, to issue a nationwide advisory on July 17, 2026 warning listed companies and regulated entities about CEO-impersonation fraud conducted via WhatsApp and Microsoft Teams.
The fraudster created or hijacked a Microsoft Teams profile carrying the name and photograph of the Italian parent company's CEO and messaged the Pune-based CFO directly while she was working from home. The message stated the CEO was occupied with a "government project" and instructed her to transfer Rs 56 lakh to two specified bank accounts, an urgency-plus-authority framing classic to CEO fraud/whale phishing. Believing the message came from her actual boss, the CFO transferred the funds without a verification call, since the request arrived on an internal-feeling, familiar corporate collaboration tool (Teams) rather than an obviously external channel like a spoofed email domain. The following morning the same impersonated profile returned with a second, larger request for Rs 1.5 crore, framed with the same urgency. This time the size and back-to-back timing of the demand raised her suspicion; she checked with her actual boss by phone, and the real CEO had no knowledge of either request, revealing the fraud. She then approached the Pimpri-Chinchwad cybercrime police, who registered an FIR and opened an investigation. No malware, deepfake audio/video, or account takeover is documented in the reporting on this specific case; the impersonation relied purely on a spoofed display name/photo plus organizational urgency and authority cues on a trusted internal messaging platform.
Lure: a Microsoft Teams message bearing the name and photo of the real Italian CEO, opening with a plausible-sounding excuse ("busy with a government project") to explain why he couldn't call and had to text instead, then an authoritative instruction to wire Rs 56 lakh to two accounts, using organizational hierarchy and manufactured urgency to bypass normal scrutiny. Tell that eventually broke the fraud: a second, much larger and equally urgent ask (Rs 1.5 crore) arriving the very next morning, a request pattern (escalating amount, back-to-back timing, still purely text-based with no phone or video contact) that felt off enough for the CFO to finally do what should have happened before the first transfer, call the real CEO directly, which immediately exposed the impersonation.
Rs 56 lakh was lost on the first transfer; the Rs 1.5 crore second request was not paid. The CFO reported the fraud, an FIR was registered at the Pimpri-Chinchwad cybercrime police station, and police opened an investigation. As of the reporting reviewed (through late July 2026), no arrest, recovery of funds, or charge-sheet had been publicly reported. The case, alongside a wider spike in similar "boss scam" incidents tracked by India's Indian Cyber Crime Coordination Centre (I4C), prompted SEBI to issue a formal advisory on July 17, 2026 warning regulated entities and listed companies about the fraud pattern.
This case shows CEO-impersonation fraud migrating from spoofed emails to internal collaboration platforms like Microsoft Teams, tools employees inherently trust as "inside the corporate perimeter," which lowers suspicion compared to an external email domain mismatch. It also demonstrates how cross-border corporate structures (an Italian parent, a Pune subsidiary, a foreign-national CEO the CFO may rarely speak to directly) create exactly the communication gap fraudsters exploit: a request framed as coming from a busy, distant executive is inherently harder for a local finance officer to sanity-check in real time. The near-miss on the second, larger demand illustrates the single highest-value control against this fraud family: mandatory out-of-band verification (a phone call, not a reply in the same chat thread) before executing any executive-originated payment instruction, a control that would have prevented the entire loss had it been applied to the first message. The case, and the SEBI advisory it and similar incidents triggered, mark a shift in Indian regulatory attention toward messaging-app-based (as opposed to email-based) executive impersonation fraud.
SEBI's July 17, 2026 "Boss Scam" advisory (issued days after this and similar incidents, based on I4C data) directs regulated entities and listed companies to: never authorize fund transfers based solely on text/chat instructions from social media, WhatsApp, or Teams-style apps; independently verify any unusual or urgent payment request through a pre-established official channel (a direct phone call to the purported requester or in-person confirmation) before acting, exactly the step the CFO in this case eventually took, which stopped the loss at the first tranche; avoid opening unexpected attachments/links in messaging apps (WhatsApp Web session-hijack malware is a related vector SEBI flagged); and maintain dual-authorization / callback verification protocols for wire transfers regardless of who appears to be requesting them. Diopter's broader take: any executive-impersonation payment request arriving purely as a chat/DM, with no synchronous verification step, should trigger callback-based confirmation before funds move, and organizations should have a named, out-of-band verification channel (not a reply to the same message) for high-value transfer approvals.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…