Impersonation Fraud: Company Scammed by Fake CEO WhatsApp Messages
A significant cybersecurity incident has been reported in Maharashtra’s Kolhapur district, involving unauthorized access to a private enterprise’s financial systems through fraudulent communication.
The Incident
Authorities allege that cybercriminals created a counterfeit profile mimicking the company’s chief executive officer, resulting in the unauthorized transfer of ₹80.50 lakh. According to official records, the perpetrators utilized the executive’s name and visual identifier to send urgent financial directives to the organization’s accounts manager, triggering two separate RTGS transactions. The affected individual, Prashant Ravindra Patil, served as the company’s accounts manager at an automobile manufacturing firm. Investigators noted that the attackers established a mobile number-based account that replicated the CEO’s identity, leveraging the executive’s personal details to execute the scheme. The fraudulent messages instructed the accounts manager to process immediate payments for business-related purposes. The compromised funds were distributed as ₹32 lakh transferred to a Gujarat-based account and ₹48.50 lakh moved to a Saharanpur, Uttar Pradesh, account.
Investigation Details
The deception was uncovered after internal verification procedures revealed discrepancies, prompting the company to file a formal complaint with law enforcement. Initial assessments indicate that the attackers exploited identity spoofing techniques to manipulate internal communication channels. Cybersecurity professionals highlight that such schemes typically involve the misuse of executive credentials, including names and profile images, to pressure employees into executing urgent financial actions without standard validation.
Cybersecurity Experts’ Advice
Law Enforcement Advisories
Law enforcement agencies have issued advisories urging businesses to adopt rigorous verification practices for digital financial requests. They advise against immediate action on suspicious communications and encourage prompt reporting of potential cyber fraud to relevant authorities.
Ongoing Investigation
The case remains under active investigation.
