WhatsApp Boss Scam How a Fake Message Led to an Alleged ₹1.40 Crore Fraud

A WhatsApp message appearing to come from a senior executive can create a serious financial risk when employees act on it without verification. In a recent Bengaluru case, fraudsters allegedly impersonated a university president to convince an accountant to transfer ₹1.40 crore. The incident highlights how criminals can exploit workplace trust, authority and urgency to carry out large-scale payment fraud.

According to a report published on October 9, 2026, Karnataka Cyber Command arrested four people in connection with the alleged fraud. The suspects reportedly used the university president’s photograph on WhatsApp and first asked about the institution’s bank balance before requesting the transfer. Police also allege that a suspicious ZIP file helped the group access information and monitor the institution’s finances. The investigation is ongoing, and these details remain allegations rather than established findings.

The incident is a reminder that a familiar name, profile photograph or convincing message does not prove someone’s identity. Businesses, educational institutions, SMEs and startup finance teams should independently verify unusual payment requests by calling the requester on a previously known number. Payments above a defined limit should require approval from a second authorised person. Employees should also avoid opening unexpected attachments, enable two-step verification on WhatsApp and email, and report suspicious messages to their IT or security team. Anyone who has already transferred money in a suspected cyber fraud should contact their bank immediately and report the incident through India’s cybercrime helpline at 1930.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

Preventing a WhatsApp boss scam requires both employee awareness and technical security. Clear payment approval procedures can stop fraudulent transfers, while endpoint protection can help reduce risks from malicious attachments and unsafe downloads. Organisations should regularly review their security practices and ensure employees know how to verify unusual instructions before acting on them.

Suspicious attachments can introduce malware into workplace systems, making endpoint security an important part of business protection. Net Protector’s npav.net offers centrally managed security settings, device control and security reporting for organisations. These measures can support a stronger security strategy, but independent payment verification and approval controls remain essential to prevent impersonation-based financial fraud.