The Rs 5.3 Crore WhatsApp Impersonation: How Fraudsters Posed as a Chairman to Loot a Company

Contents

A single fake WhatsApp profile — a stolen name and photo — was enough to convince a trusted accountant to wire away crores. Here’s how the scam worked, and how it unravelled.

Rajasthan, India Cyber Crime Branch, State Police Case reported

On paper, it should have been an ordinary instruction from the boss: an urgent transfer, two bank accounts, a familiar name and photo on WhatsApp. That was all it took for an accountant at Galaxy Mining Private Limited to move Rs 5.3 crore of company funds into the hands of strangers. The case, now under investigation by Rajasthan Police’s Cyber Crime Branch, has become one of the more striking recent examples of executive impersonation fraud hitting India’s corporate sector.

₹5.3 Cr

Amount defrauded

2

Accounts used

1

Arrest so far

How the Scam Was Engineered

According to the complaint filed through the national cybercrime helpline, fraudsters first gathered publicly available information about the company’s chairman, Deependra Singh Rathore — including his name and a photograph likely lifted from social media or public listings. They used this to set up a WhatsApp account impersonating him, complete with a matching display picture, and reached out to the company’s accountant from an unfamiliar number.

The message carried the unmistakable weight of authority: instructions to urgently transfer funds to two specified bank accounts. Seeing what appeared to be his employer’s name and face on the screen, the accountant — who was authorised to execute company transactions — didn’t pause to verify the request through a phone call or in person. He transferred the full amount, Rs 5.3 crore, via online banking.

Why It Worked This wasn’t a technically sophisticated hack. No servers were breached, no malware installed. The entire fraud rested on social engineering: exploiting trust in a familiar name, a familiar face, and the everyday pressure of following instructions from a senior figure quickly.

Following the Money: The Investigation

Given the scale of the fraud, a special investigation team was formed under senior police officers to trace the transaction trail. Investigators worked through bank records, mobile numbers, and digital transaction logs linked to the two accounts that received the funds.

That trail led to Rahul Ashok, a 32-year-old from Pune, Maharashtra. With help from Maharashtra Police, Rajasthan’s Cyber Crime team arrested him and brought him to Jaipur on transit remand. During questioning, he reportedly admitted to supplying bank accounts to the fraud syndicate in exchange for commissions, and to helping move the stolen money through the banking system.

A Fake Firm, a Rs 50 Crore Credit Limit

What investigators uncovered next points to gaps well beyond one gullible accountant. Police allege that Rahul, on the direction of a Pune-based associate identified as Amit Singh, registered a fictitious business using forged documents — and that a bank subsequently opened a current account for this shell firm with a credit limit of Rs 50 crore. It was this account that allegedly received the Rs 5.3 crore in fraud proceeds.

Police say Rahul opened at least three additional accounts for the wider syndicate. As soon as money landed in these accounts, it was rapidly moved through multiple further accounts — a classic “layering” technique used to obscure the money trail and make recovery difficult. Investigators are now examining whether bank officials played any role in allowing such accounts to be opened and approved for large credit limits with minimal scrutiny.

Part of a Wider Pattern

This is not an isolated case. Executive-impersonation fraud over WhatsApp has repeatedly targeted Indian institutions in recent years — from corporate accountants to government offices. In a similar case in Uttar Pradesh, an accountant working for a state minister was misled into transferring over Rs 2 crore after fraudsters posed as the minister’s son using a stolen photo and a new number. The playbook is nearly identical each time: borrow a trusted identity, create urgency, and strike before anyone can verify the request through a second channel.

How Companies Can Guard Against This

  • Verify out-of-band: Any urgent fund-transfer request — especially over WhatsApp or a new number — should be confirmed with a phone call to a known, saved number before action is taken.
  • Dual authorisation: High-value transfers should require sign-off from more than one authorised person, not a single accountant acting alone.
  • Slow down “urgency”: Fraudsters rely on urgency to short-circuit normal checks. A genuine emergency can withstand a five-minute verification call.
  • Educate finance teams: Regular awareness training on impersonation and social-engineering scams should be as routine as any other compliance training.
  • Bank-side scrutiny: This case also highlights how easily shell firms can secure large credit limits — a reminder that banks’ own KYC and account-opening diligence matters just as much as corporate vigilance.

What Happens Next

Only one person has been arrested so far. Police say the investigation continues into the wider network, including the alleged kingpin identified as Amit Singh, and into other bank accounts and mobile numbers connected to the fraud. Whether the company recovers any of the Rs 5.3 crore will likely depend on how quickly the layered transactions can be traced and frozen — a race that grows harder with every account the money passes through.

For now, the case stands as a stark reminder that in the age of instant messaging, the most convincing “chairman” giving urgent instructions might just be a stolen photo and a stranger on the other end of the line.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *