
Two mule-account operators are behind bars. The Managing Director whose identity was stolen never sent a single message. Here is what the case means for corporate liability, employee training, and the legal remedies actually available to victims.
Afinance executive at a Hyderabad company opened WhatsApp to a familiar face — the Managing Director’s name, the Managing Director’s photograph — asking for an urgent fund transfer. Nothing about the message looked wrong. By the time anyone picked up the phone to check, ₹4.70 crore had already left the company’s accounts. This is the anatomy of what investigators now call a “WhatsApp Boss Fraud,” and it is becoming one of the most consequential corporate cyber threats in India.
Case at a Glance
Bureau
Telangana Cyber Security Bureau (TGCSB)
Modus operandi
Fake WhatsApp profile impersonating the company’s Managing Director
Amount defrauded
₹4.70 crore, transferred to multiple mule accounts
Arrests
Two men held for supplying and operating mule bank accounts used to launder the funds
Statutes invoked
Sections 318(4) & 319(2), Bharatiya Nyaya Sanhita; Section 66-D, IT Act, 2000
Status
Accused remanded to judicial custody; investigation continues to trace remaining funds and absconding accused
How the Fraud Unfolded
According to the TGCSB, the scheme began the way most executive-impersonation frauds do: quietly, and through a channel employees are conditioned to trust. A fraudster registered a WhatsApp number using the Managing Director’s actual name and profile photograph — both easily lifted from LinkedIn, a company website, or a press photograph — and reached out to an employee with an urgent, plausible request for a fund transfer. Believing the instruction to be genuine, the employee moved money across multiple bank accounts specified by the impersonator. Only later, when the real Managing Director was contacted directly, did the company realise the instruction had never come from him at all.
Investigators traced the money through the banking system rather than through WhatsApp itself, since the app offers little forensic value once an account is deleted. Technical analysis of the destination accounts led to two men — one who allegedly supplied a “mule” current account into which ₹1.80 crore was routed, and another who had arranged that account for the wider fraud network. That single account also showed unrelated suspicious credits exceeding ₹2.49 crore and links to cybercrime complaints in Maharashtra, Rajasthan, and Tamil Nadu — a pattern that points to an organised, inter-state money-laundering layer sitting underneath the impersonation itself.
“Do not trust a WhatsApp profile merely because it displays the name or photograph of a known person — these can be easily copied and misused by fraudsters.”— TGCSB Director, on the investigation
The Legal Architecture Behind the Arrest
The FIR in this matter was registered under a combination of the newly enforced criminal code and the IT Act — a pairing that is quickly becoming standard for impersonation-driven financial fraud in India.
Provisions Invoked
BNS § 318(4)
Cheating and dishonestly inducing delivery of property — the core provision covering the fraudulent inducement that caused the company to part with ₹4.70 crore.
BNS § 319(2)
Cheating by personation — directly applicable where the offender impersonates a specific, identifiable individual, here the Managing Director, to deceive the victim.
IT Act § 66-D
Punishes cheating by personation using a computer resource or communication device — the digital-impersonation counterpart that captures the WhatsApp-based deception specifically.
Note what is conspicuously absent so far: charges against the actual impersonator, who remains unidentified. The two men arrested are alleged to be downstream facilitators — mule-account suppliers who monetised the fraud rather than the individuals who created the fake profile. This is typical of how these cases resolve in the first instance: the banking trail is easier to follow than the identity behind an anonymous international number, so enforcement action often begins with the money before it reaches the mind behind the scam.
Who Can Be Held Liable — And For What
A case like this rarely produces a single liable party. Indian cyber-fraud law, read together with banking regulation and corporate governance norms, spreads exposure across several actors.
The Impersonator
Primary liability under BNS 318(4), 319(2) and IT Act 66-D for cheating by personation. Conviction requires identification — often the hardest part of these investigations, given the use of disposable numbers and offshore infrastructure.
Mule Account Holders
Liable not only as accessories to cheating but independently under IT Act provisions on facilitating cybercrime, and frequently under the Prevention of Money Laundering Act where the proceeds are laundered through multiple accounts, as alleged here.
The Company
Ordinarily the victim, but internal control failures — a single employee able to authorise a multi-crore transfer without dual verification — can expose the company to shareholder or insurer scrutiny, and complicate recovery claims.
Receiving Banks
RBI’s KYC and mule-account monitoring norms impose a duty of diligence on banks that open and operate accounts later found to be laundering conduits. Repeated red flags — as seen in this account’s history — can support a negligence claim against the bank.
Why “Boss Fraud” Keeps Working
This is not an isolated incident — it is a pattern replicating across Indian corporates with unsettling regularity, and the reasons are structural rather than technological. WhatsApp offers no verified-identity layer for business communication the way email domains or digital signatures do. A display name and profile photo are trivially copied, and the platform’s end-to-end encryption — while a genuine privacy safeguard — also means neither WhatsApp nor law enforcement can intervene in real time once a message is sent. Combine that with corporate cultures where an instruction from an MD is rarely questioned, and the fraud exploits hierarchy as much as it exploits technology.
The involvement of mule accounts linked to complaints in three other states also signals something companies should not overlook: these are not opportunistic individual scammers but organised networks that treat mule-account sourcing as a service line, available to any fraud operation willing to pay a commission — reportedly as little as a few lakh rupees in this case, against a ₹4.70 crore haul.
Advisory — Minimum Safeguards for Companies
- 01Verbal verification, always. No fund transfer above a defined threshold should proceed on a chat instruction alone — a callback to a known, saved number is non-negotiable before execution.
- 02Dual authorisation. Structure banking mandates so no single employee can both receive an instruction and execute a high-value transfer without a second sign-off.
- 03Named-contact protocol. Circulate an internal register of verified numbers for the MD and other signatories; treat any request from an unlisted number as suspect by default.
- 04Immediate escalation path. Once a suspicious transfer is discovered, contact the bank and file a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline within the “golden hour” to improve fund-freeze chances.
- 05Legal counsel on standby. Early engagement with a cyber law advisor helps preserve evidence correctly, frame the police complaint under the right provisions, and pursue civil recovery in parallel with the criminal process.
The Recovery Reality
Companies often assume that an arrest means recovery. It does not, necessarily. Even where mule-account holders are apprehended, the funds have typically already been layered through several accounts and, in cross-border operations, moved out of the domestic banking system entirely — often converted through cryptocurrency exchanges or shell remittances. Recovery is meaningfully more likely when a company acts within hours of the fraud, using the “golden hour” freeze mechanism through the 1930 cybercrime helpline, than when it waits for the police investigation to run its course. This is precisely why the legal response to such fraud has to begin before the fraud happens — through governance controls that make the deception harder to execute in the first place.
If your organisation has been targeted by a similar impersonation scam, time-sensitive action — freezing transfers, filing the right FIR provisions, and engaging with the bank’s fraud desk — materially affects the odds of recovery. Reach out for a confidential consultation on your immediate options and longer-term governance safeguards.