The ‘Boss Scam’ Haunting India: What Is It and How Does It Happen?
— Surya Prakash Josyula
One regular morning at the office, the accounts team received an email from the boss:
“Please transfer this payment to this new bank account immediately.”
It was a significant amount. However, the subject had already been discussed with the boss earlier. The email ID, the signature, and the total payable amount were all genuine. There was no obvious reason for suspicion; it looked like standard routine business. Without overthinking, the accounts team processed the payment.
A little later, the boss walked into the office and clarified: “I never sent any such email.”
In an instant, everyone realized what had happened. But by then, the money was already gone. This is the Boss Scam.
While it might sound like a scene from a thriller, these attacks are happening in real life, and warnings are already being issued across India.
How Does the Scam Begin?
Here lies the real twist: the hacker did not target the CEO first. Instead, they began with a regular employee’s email account, which is often far easier to compromise.
Once inside, the hacker gained access to critical internal details:
Who reports to whom?
Who is the CEO?
What are everyone’s specific responsibilities?
Who interacts regularly with key executives?
In the past, gathering this intelligence took a substantial amount of time. Now, artificial intelligence does the heavy lifting.
In a controlled attack simulation conducted by cybersecurity firm Barracuda, an attacker used Microsoft Copilot within a compromised employee account to analyze the company’s hierarchy and pinpoint senior executives. AI did not hand the hacker an exploit out of thin air; rather, it rapidly helped identify the highest-value targets inside the organization.
The Next Target: The CEO
Sending an outright suspicious email directly to the CEO risks immediate detection. Instead, the attacker analyzed the compromised employee’s email history:
How does this employee write?
What tone and phrasing do they use?
What active projects or discussions are ongoing?
Using these contextual details, the attacker generated a convincing phishing email with AI and sent it to the CEO.
This approach is far more dangerous than standard spam. The message came from a legitimate internal address and read like an authentic follow-up to an existing conversation. The CEO clicked the link, allowing the attacker to hijack the authenticated session and take over the CEO’s mailbox.
What Did the Hacker Find in the CEO’s Inbox?
A CEO’s inbox can contain thousands of sensitive emails: bank transactions, invoices, investment strategies, property deals, upcoming schedules, and correspondence with finance teams.
The attacker did not have to manually read through years of messages. With AI, they simply queried:
“What are the recent financial emails?”
“Which large payments are scheduled soon?”
“What transactions are currently pending approval?”
Within seconds, AI surfaced a pending wire transfer of $247,500 (over ₹2 crore).
Diverting the Funds
The final step was straightforward. From the compromised CEO account, the attacker emailed the finance team requesting an update to the beneficiary bank details for the pending transaction.
Seeing no cause for alarm—since the request came from the real CEO’s address—the finance team made the change. The funds were wired directly to the attacker’s account.
The critical takeaway: The hacker did not create a fake persona. They weaponized the real boss’s authenticated account.
Why Is This a Major Threat in India?
The Indian Cyber Crime Coordination Centre (I4C) has already issued warnings regarding “Boss Scams,” where cybercriminals impersonate senior executives to push high-value financial transfers, specifically targeting finance and accounts departments.
When this occurs in large enterprises or growing businesses, the impact extends beyond a single compromised inbox. It can derail major vendor settlements, property acquisitions, or investment transfers. One unauthorized approval can compromise an entire financial chain.
The Boss Scam is not simple phishing. It is a targeted exploitation of internal corporate trust to move real money.






