google.com, pub-8701563775261122, DIRECT, f08c47fec0942fa0
Hollywood News

SEBI warns listed firms, regulated entities against ‘Boss Scam’ involving CEO, MD impersonation

Mumbai (Maharashtra) [India]July 17 (ANI): The Securities and Exchange Board of India (SEBI) on Friday warned listed companies and regulated entities against an emerging cyber scam known as ‘Boss Scam’, where fraudsters impersonate Chief Executive Officers (CEOs), Managing Directors (MDs) and other senior officials to trick financial executives into transferring funds.

SEBI said the advisory was issued after the Indian Cyber ​​Crime Coordination Center (I4C) informed the market regulator about the increasing trend of such scams.

SEBI said it has issued this Press Release as follows: “I4C has observed an emerging trend in cybercrime called “Boss Scam” or CEO/MD impersonation scam where fraudsters target high-ranking officials/financial executives and force them to transfer funds to fraudsters.”

According to SEBI, fraudsters are targeting CEOs and other senior officials through email, WhatsApp and other social media platforms. They then impersonate these senior executives, contact financial officials or other employees, and direct them to transfer money to accounts controlled by the fraudsters.

The regulator said cybercriminals use two main methods to carry out fraud.

In the first method, scammers use deepfake technology, including AI-generated voice cloning, fake video calls, and fake social media groups, to impersonate CEOs or MDs.

Finance officers are then instructed to transfer the money to a specific bank account. In some cases, they are also told not to disclose the transaction, claiming that the transaction relates to Unpublished Price Sensitive Information (UPSI).

In the second method, scammers send a compressed .zip file via messages. The file contains a malicious executable as well as a Dynamic Link Library (DLL) file. If the file is opened on a Windows computer, malware is installed that can hijack the user’s active WhatsApp Web session.

SEBI said that after gaining access to the finance officer’s WhatsApp account, the fraudsters contacted the accounts or finance employees and instructed them to make urgent payments to certain bank accounts.

In some cases, if attackers gain full control of the device, they secretly modify the contact list by recording the fraudster’s phone number under the name of the CEO or MD, and then use that number to issue payment instructions.

The market regulator has advised listed companies and regulated entities to exercise caution and verify all payment requests received via WhatsApp, email or social media platforms by calling senior officials directly. It also advised companies not to transfer funds solely based on instructions received through social media platforms.

SEBI has also appealed to organizations not to upload executables received from unknown or unverified sources without verifying the identity of the sender, even if they appear to be sent by a known person. Users were also advised to log out of WhatsApp Web sessions that are not actively used.

The regulator has asked companies to immediately report any such incidents of fraud or cybercrime by calling the national cybercrime helpline 1930 or reporting it through the National Cybercrime Reporting Portal.

Disclaimer: This story was published from a news agency feed without modifications to the text.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button