SEBI Issues Warning to Listed Entities Regarding Boss Scam and CEO Impersonation Threats

0
16
Office desk setup with a laptop showing cybersecurity warnings and a smartphone.
Office desk setup with a laptop showing cybersecurity warnings and a smartphone.

Understanding the Boss Scam Targeting Corporate Leadership

The Securities and Exchange Board of India has issued a public caution to all regulated entities and listed companies following an intelligence update from the Indian Cyber Crime Coordination Centre regarding an emerging cybercrime trend. Locally and internationally referred to as the Boss Scam or CEO and MD impersonation fraud, the activity involves malicious actors targeting top corporate executives and finance personnel to manipulate financial transactions.

According to official details, perpetrators reach out to chief executive officers or high-ranking officials via electronic mail or messaging platforms like WhatsApp. By impersonating leadership figures, bad actors direct subordinate employees to execute unauthorized money transfers to designated mule accounts. Perpetrators often pressure staff to complete these transfers immediately, sometimes claiming the instructions relate to confidential unpublished price-sensitive information to discourage internal verification.

Tactics Involving Deepfakes and Malware Archives

The advisory highlights two primary strategies employed by fraudsters to deceive corporate teams. Under the first approach, criminals utilize deep-fake technology, including voice cloning and artificial intelligence on video calls, alongside fraudulent social media groups that imitate senior management. These methods are deployed to convince finance officers that they are communicating directly with their actual superiors.

The second tactic involves transmitting a compressed archive file containing malicious executable files and dynamic link library components. When a recipient extracts and executes these files on a desktop or laptop operating system, a Trojan dropper initiates. This malware compromises system security, hijacks active web messaging sessions, and allows unauthorized access to compromise communication accounts or alter device contact directories.

Advisory Measures for Listed Firms

To mitigate these emerging cybersecurity risks, regulatory authorities have outlined specific precautionary steps for businesses and their employees:

  • Remain vigilant and cross-verify any fund transfer or directive received via email, messaging applications, or social media by placing a direct telephone call to the senior official.
  • Refrain from transferring corporate funds solely based on instructions communicated through digital platforms.
  • Avoid downloading or executing attachments from unknown senders, and verify the identity of senders through alternative communication channels.
  • Sign out of inactive web messaging sessions promptly.
  • Report any suspicious cyber incidents or fraudulent communication immediately through the official national cybercrime helpline or web portal.

Primary source: This independent news summary is based on official information from Securities and Exchange Board of India. Read the original document for complete details.