SEBI warns of AI impersonation scams with fraudsters posing as company CXOs
India's market regulator, SEBI, has issued a warning to regulated entities and listed companies about a rising "Boss Scam" where fraudsters use AI to impersonate senior executives and trick finance teams into transferring funds.
Intelligence analysis by Gemini 2.5 Flash

The Securities and Exchange Board of India (SEBI) has alerted companies to sophisticated cyber fraud, dubbed the "Boss Scam," which leverages AI-generated deepfakes and voice cloning to mimic CXOs. These scammers manipulate finance personnel into making urgent, confidential fund transfers to fraudulent accounts, often by exploiting digital communication platforms or deploying malware.
Imagine a tricky person pretending to be your school principal using a super clever voice changer or a fake video call. They might tell your teacher to quickly send money to a secret account for a 'very important' school project. SEBI, like a grown-up watching out for everyone's money, is telling companies to be super careful and always double-check with the real boss before sending any money, because these fake calls are getting really good thanks to smart computer tricks.
Analysis
The Evolving Threat of the 'Boss Scam'
The Securities and Exchange Board of India (SEBI) has sounded an alarm regarding a sophisticated cyber fraud, colloquially known as the "Boss Scam," which is increasingly targeting regulated entities and listed companies across India. This scam represents a significant escalation in cybercrime, moving beyond traditional phishing tactics to incorporate advanced artificial intelligence technologies. The Indian Cyber Crime Coordination Centre (I4C) has specifically highlighted the use of AI-generated deepfakes and voice cloning, which enable fraudsters to create highly convincing impersonations of chief executives and other senior officials. This technological leap makes it significantly harder for employees to discern legitimate instructions from fraudulent ones, posing a severe risk to corporate financial security.
Dual Modalities of Deception
The article outlines two primary strategies employed by these fraudsters. The first, "Strategy A – AI-powered impersonation," involves scammers directly mimicking company leaders through AI-generated video calls, voice cloning, or fake social media groups. They then instruct finance officers to transfer funds to mule bank accounts, often under the guise of urgent, confidential transactions related to Unpublished Price Sensitive Information (UPSI). This tactic preys on the urgency and perceived authority of senior management, compelling employees to bypass standard verification procedures. The second method, "Strategy B – Malicious ZIP archive," is more technically intricate. Fraudsters send a compressed .zip file containing malware. Once opened, this malicious software can hijack the victim's WhatsApp Web session or compromise their entire device. This allows attackers to impersonate the executive from the employee's own compromised account or alter contact details to issue fraudulent payment instructions, effectively turning the employee's own communication channels against them.
SEBI's Proactive Stance and Corporate Vigilance
In response to this escalating threat, SEBI has issued clear advisories aimed at bolstering corporate defenses. The regulator emphasizes the critical importance of independent verification: employees must call senior officials directly to confirm any financial transaction requests received via digital platforms like WhatsApp, email, or Microsoft Teams, rather than relying solely on digital instructions. Furthermore, companies are urged to educate their staff against installing executable files from unverified senders and to ensure that inactive WhatsApp Web sessions are promptly logged out to mitigate account hijacking risks. This proactive warning from SEBI underscores the regulator's commitment to safeguarding the integrity of India's financial markets and highlights the shared responsibility of companies to implement robust cybersecurity measures and foster a culture of skepticism and verification among their employees to counter these increasingly sophisticated AI-driven frauds.
Key points
- SEBI has warned Indian regulated entities and listed companies about the "Boss Scam."
- Fraudsters are using AI-generated deepfakes and voice cloning to impersonate CXOs.
- Scammers instruct finance teams to transfer funds to mule accounts, often citing urgency and confidentiality.
- Another tactic involves sending malicious ZIP files to hijack WhatsApp Web sessions or compromise devices.
- SEBI advises independent verification of all digital financial instructions and caution against installing unverified executable files.
SEBI's timely warning could significantly raise awareness among regulated entities and listed companies, prompting them to implement stronger verification protocols and cybersecurity training. This proactive measure has the potential to prevent numerous instances of fraud, thereby protecting corporate assets and investor confidence in the Indian market.
Despite SEBI's advisories, the increasing sophistication of AI-powered deepfakes and voice cloning could make these scams incredibly difficult to detect, leading to substantial financial losses for companies. The rapid evolution of these fraudulent techniques may outpace corporate defense mechanisms, leaving organizations vulnerable to persistent and costly cyberattacks.



