SEBI Warns Companies of 'Boss Scams' Using AI Deepfakes

TECHNOLOGY
Whalesbook Logo
AuthorAnanya Iyer|Published at:
SEBI Warns Companies of 'Boss Scams' Using AI Deepfakes

The Securities and Exchange Board of India (SEBI) and the Indian Cyber Crime Coordination Centre (I4C) have issued an urgent warning about 'Boss Scams.' Fraudsters are using AI-generated deepfakes and malware to impersonate senior executives and trick finance teams into making unauthorized payments. Investors should be aware that these cyber threats pose significant operational risks to listed companies and can lead to the spread of fraudulent stock information.

The Securities and Exchange Board of India (SEBI), in coordination with the Indian Cyber Crime Coordination Centre (I4C), has issued a serious warning to listed firms regarding a rising cyber threat known as 'Boss Scams.' This fraud involves criminals impersonating CEOs, Managing Directors, and other senior executives to manipulate company employees—specifically those in finance and accounts departments—into transferring funds or sharing sensitive information.

The scams rely on highly sophisticated technology. Fraudsters are using AI-generated voice cloning and deepfake video calls to convincingly mimic the identity of senior leadership. By appearing in fake video calls or speaking with a familiar voice, they pressure employees to authorize urgent payments, often claiming the transactions are confidential or related to critical business matters. This method exploits the trust employees place in their leadership, making them more likely to bypass standard security checks.

Beyond simple impersonation, the attackers are using technical methods to gain deeper access to corporate systems. A common technique involves sending malicious files, often compressed as .zip archives and disguised as official documents. If an employee downloads and opens these files, it can install malware that hijacks their WhatsApp Web session. This allows the attacker to read messages and send fraudulent requests from the victim’s own account, making the scam appear highly authentic to other colleagues.

For investors, this emerging threat is significant for several reasons. Successful attacks can lead to direct financial losses for companies, which may impact quarterly margins and overall cash flow. Furthermore, there is a reputational risk if attackers gain control of corporate messaging channels to spread misinformation. The Bombay Stock Exchange (BSE) has already cautioned investors against deepfake videos that misuse the identities of its leadership to provide fake stock tips or investment advice, highlighting the potential for these scams to cause direct harm to market participants.

As these threats evolve, companies are tightening their internal verification protocols. Investors may notice that firms are increasingly implementing stricter rules for payments and sensitive data sharing, which is a necessary defensive step. The primary monitorable for stakeholders will be how effectively companies train their staff to independently verify urgent requests through known, trusted channels rather than relying on digital impersonations. If an unusual or high-value request arrives via messaging apps, companies are urging employees to always verify it by contacting the executive through a pre-established, trusted phone number.

Disclaimer: This article is published for informational purposes only. This is not a buy sell recommendation.