A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO demanded an urgent transfer.
Social Engineering Examples·3 sources
On the morning of July 13, 2026, while working from home, the 49-year-old CFO of the Pune office of an Italian-headquartered engineering firm received a Microsoft Teams message from a profile displaying the name and photo of the company's actual Italian CEO. The message claimed the CEO was tied up with a government project and instructed her to transfer Rs 56 lakh to two bank accounts; she complied.
The next morning the same impersonated profile sent a second, larger request for Rs 1.5 crore. The escalation and timing made her suspicious, and she verified by phone with the real CEO, who confirmed he had sent neither message. She then filed a complaint with the Pimpri-Chinchwad cybercrime police, who registered an FIR and opened an investigation.
The incident was reported by The Indian Express, and it surfaced amid a wave of similar "boss scam" cases that prompted India's securities regulator, SEBI, to issue a nationwide advisory on July 17, 2026 warning listed companies and regulated entities about CEO-impersonation fraud conducted via WhatsApp and Microsoft Teams.
The fraudster created or hijacked a Microsoft Teams profile carrying the name and photograph of the Italian parent company's CEO and messaged the Pune-based CFO directly while she was working from home. The message stated the CEO was occupied with a "government project" and instructed her to transfer Rs 56 lakh to two specified bank accounts, an urgency-plus-authority framing classic to CEO fraud/whale phishing.
Believing the message came from her actual boss, the CFO transferred the funds without a verification call, since the request arrived on an internal-feeling, familiar corporate collaboration tool (Teams) rather than an obviously external channel like a spoofed email domain. The following morning the same impersonated profile returned with a second, larger request for Rs 1.5 crore, framed with the same urgency.
This time the size and back-to-back timing of the demand raised her suspicion; she checked with her actual boss by phone, and the real CEO had no knowledge of either request, revealing the fraud. She then approached the Pimpri-Chinchwad cybercrime police, who registered an FIR and opened an investigation. No malware, deepfake audio/video, or account takeover is documented in the reporting on this specific case; the impersonation relied purely on a spoofed display name/photo plus organizational urgency and authority cues on a trusted internal messaging platform.
Lure: a Microsoft Teams message bearing the name and photo of the real Italian CEO, opening with a plausible-sounding excuse ("busy with a government project") to explain why he couldn't call and had to text instead, then an authoritative instruction to wire Rs 56 lakh to two accounts, using organizational hierarchy and manufactured urgency to bypass normal scrutiny.
Tell that eventually broke the fraud: a second, much larger and equally urgent ask (Rs 1.5 crore) arriving the very next morning, a request pattern (escalating amount, back-to-back timing, still purely text-based with no phone or video contact) that felt off enough for the CFO to finally do what should have happened before the first transfer, call the real CEO directly, which immediately exposed the impersonation.
Rs 56 lakh was lost on the first transfer; the Rs 1.5 crore second request was not paid. The CFO reported the fraud, an FIR was registered at the Pimpri-Chinchwad cybercrime police station, and police opened an investigation. As of the reporting reviewed (through late July 2026), no arrest, recovery of funds, or charge-sheet had been publicly reported.
The case, alongside a wider spike in similar "boss scam" incidents tracked by India's Indian Cyber Crime Coordination Centre (I4C), prompted SEBI to issue a formal advisory on July 17, 2026 warning regulated entities and listed companies about the fraud pattern.
This case shows CEO-impersonation fraud migrating from spoofed emails to internal collaboration platforms like Microsoft Teams, tools employees inherently trust as "inside the corporate perimeter," which lowers suspicion compared to an external email domain mismatch. It also demonstrates how cross-border corporate structures (an Italian parent, a Pune subsidiary, a foreign-national CEO the CFO may rarely speak to directly) create exactly the communication gap fraudsters exploit: a request framed as coming from a busy, distant executive is inherently harder for a local finance officer to sanity-check in real time.
The near-miss on the second, larger demand illustrates the single highest-value control against this fraud family: mandatory out-of-band verification (a phone call, not a reply in the same chat thread) before executing any executive-originated payment instruction, a control that would have prevented the entire loss had it been applied to the first message.
The case, and the SEBI advisory it and similar incidents triggered, mark a shift in Indian regulatory attention toward messaging-app-based (as opposed to email-based) executive impersonation fraud.
SEBI's July 17, 2026 "Boss Scam" advisory (issued days after this and similar incidents, based on I4C data) directs regulated entities and listed companies to: never authorize fund transfers based solely on text/chat instructions from social media, WhatsApp, or Teams-style apps; independently verify any unusual or urgent payment request through a pre-established official channel (a direct phone call to the purported requester or in-person confirmation) before acting, exactly the step the CFO in this case eventually took, which stopped the loss at the first tranche; avoid opening unexpected attachments/links in messaging apps (WhatsApp Web session-hijack malware is a related vector SEBI flagged); and maintain dual-authorization / callback verification protocols for wire transfers regardless of who appears to be requesting them.
Diopter's broader take: any executive-impersonation payment request arriving purely as a chat/DM, with no synchronous verification step, should trigger callback-based confirmation before funds move, and organizations should have a named, out-of-band verification channel (not a reply to the same message) for high-value transfer approvals.
Social Engineering Examples. “Pune Italian Engineering Firm CFO Microsoft Teams Boss-Scam (Rs 56 Lakh Loss, 2026)”. Accessed 19 September 2026. https://socialengineeringexamples.com/pune-teams-boss-scam-cfo-2026
the attacker likely researched the Pune subsidiary's organizational and ownership structure, consistent with using public sources such as LinkedIn, company websites, and press coverage to identify the Italian parent company's CEO by name and photograph, and to identify the CFO as the local finance decision-maker who would act on his instructions.
Public executive identifying information (a CEO's name, role, and photograph on a company website, LinkedIn, or in press coverage) is very difficult to eliminate for any public-facing senior executive; the realistic control assumes this exposure exists and instead hardens the payment-verification process it later gets used against, per Stage 5's countermeasure.
the attacker built or hijacked a Microsoft Teams profile carrying the real CEO's name and a photo plausibly pulled from public sources (company website, LinkedIn, press headshots), and staged one or more receiving 'mule' bank accounts to accept the fraudulent transfer.
Enterprise Microsoft 365/Teams administrators can enable external-sender and unverified-account warning labels, restrict who can message internal staff under an executive's display name from outside the tenant, and monitor for newly created accounts impersonating senior officials.
the attacker messaged the CFO directly on Microsoft Teams, a collaboration tool employees typically treat as inherently internal and lower-risk than external email, rather than using an obviously external channel.
Train employees that a message's legitimacy depends on verified sender identity, not on which application it arrives through; internal collaboration tools like Teams should receive the same scrutiny for high-stakes financial requests as external email.
the message explained the CEO's unavailability with a plausible excuse ("busy with a government project") to justify texting instead of calling, then issued an urgent, high-authority instruction to wire funds, leveraging hierarchical deference to suppress the CFO's normal scrutiny.
Treat an "unavailable executive plus urgent, confidential payment" narrative as a recognized fraud script (as flagged in SEBI's advisory) and train finance staff to respond to unavailability or secrecy claims with mandatory verification rather than compliance.
Payment instruction and fund transfer (objective completion, first tranche): the CFO transferred Rs 56 lakh to two specified bank accounts without an out-of-band verification call, completing the attacker's financial objective for the initial request.
Require mandatory out-of-band verification, a phone call to a known, pre-established number rather than a reply in the same chat thread, before executing any executive-originated wire transfer; applied here, this single control would have prevented the entire Rs 56 lakh loss.
the same impersonated profile returned the next morning demanding a much larger Rs 1.5 crore transfer; the size and back-to-back timing of this second ask triggered the CFO's suspicion, leading her to place an out-of-band phone call to the real CEO, which exposed the impersonation and stopped further loss.
Maintain dual-authorization and callback-verification protocols for all high-value wire transfers regardless of the apparent requester; this is the control that actually worked in this case, since the CFO's own out-of-band call at this stage caught the fraud before the larger second payment could be sent.
Browse by what this case has in common with others in the library.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
Hours before Maharashtra's 2024 assembly election polling, BJP-amplified audio clips purporting to catch opposition leaders Supriya Sule and Nana Patole.
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…