Impersonation Fraud: Company Scammed by Fake CEO WhatsApp Messages

www.news4hackers.com-impersonation-fraud-company-scammed-by-fake-ceo-whatsapp-messages-impersonation-fraud-company-scammed-by-fake-ceo-whatsapp-messages

A significant cybersecurity incident has been reported in Maharashtra’s Kolhapur district, involving unauthorized access to a private enterprise’s financial systems through fraudulent communication.

The Incident

Authorities allege that cybercriminals created a counterfeit profile mimicking the company’s chief executive officer, resulting in the unauthorized transfer of ₹80.50 lakh. According to official records, the perpetrators utilized the executive’s name and visual identifier to send urgent financial directives to the organization’s accounts manager, triggering two separate RTGS transactions. The affected individual, Prashant Ravindra Patil, served as the company’s accounts manager at an automobile manufacturing firm. Investigators noted that the attackers established a mobile number-based account that replicated the CEO’s identity, leveraging the executive’s personal details to execute the scheme. The fraudulent messages instructed the accounts manager to process immediate payments for business-related purposes. The compromised funds were distributed as ₹32 lakh transferred to a Gujarat-based account and ₹48.50 lakh moved to a Saharanpur, Uttar Pradesh, account.

Investigation Details

The deception was uncovered after internal verification procedures revealed discrepancies, prompting the company to file a formal complaint with law enforcement. Initial assessments indicate that the attackers exploited identity spoofing techniques to manipulate internal communication channels. Cybersecurity professionals highlight that such schemes typically involve the misuse of executive credentials, including names and profile images, to pressure employees into executing urgent financial actions without standard validation.

Cybersecurity Experts’ Advice

According to official records, the perpetrators utilized the executive’s name and visual identifier to send urgent financial directives to the organization’s accounts manager, triggering two separate RTGS transactions.
A senior cybersecurity analyst and former law enforcement official emphasized the necessity of implementing layered verification protocols for high-value transactions. They recommended that organizations avoid authorizing payments based solely on digital messages, profile visuals, or account details. Instead, staff should confirm instructions through verified contact methods, such as direct phone calls using official communication channels.

Law Enforcement Advisories

Law enforcement agencies have issued advisories urging businesses to adopt rigorous verification practices for digital financial requests. They advise against immediate action on suspicious communications and encourage prompt reporting of potential cyber fraud to relevant authorities.

Ongoing Investigation

The case remains under active investigation.



About Author

en_USEnglish