Executive Impersonation for Urgent Transfers — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: Critical | View Full Scam Details
🛡️ Want to check if you've received this scam?
Check This Scam on BharatSecure →Executive Impersonation UPI Scam (2025): How Fraudsters Pose as Your CEO to Steal Lakhs — India Warning
Indian companies are losing crores to a fast-growing Business Email Compromise (BEC) tactic where fraudsters impersonate senior executives to trick finance staff into making unauthorised UPI transfers. If you work in accounts, finance, or operations at any Indian business, this scam is targeting people exactly like you — right now.
What Is the Executive Impersonation for Urgent Transfers Scam?
This scam — known globally as Business Email Compromise (BEC) — involves callers or message-senders fraudulently posing as a company's CEO, CFO, or other senior executive to pressure finance employees into making immediate fund transfers. In India, the fraud has evolved to exploit UPI's speed, WhatsApp's informality, and corporate tools like SBI YONO and HDFC NetBanking.
Targets are primarily urban professionals, small business owners, and finance-team employees. Reported losses in cases documented publicly run from ₹1 lakh to ₹10 lakh per incident, with industry-level losses from such patterns reportedly exceeding ₹350 crore in a single year. The Ministry of Home Affairs (MHA) and CERT-In have both flagged Business Email Compromise as a priority threat to Indian enterprises.
BharatSecure's threat-intelligence database has catalogued 13 fraudulent UPI identifiers linked to this scam pattern, verified through NPCI cross-checks and community reports submitted by BharatSecure users.
Exactly How This Scam Works — Step by Step
Research phase. Fraudsters scour LinkedIn, Facebook, and corporate websites to map company hierarchies — names, designations, reporting lines, and financial processes. They may monitor publicly visible email patterns to mimic internal communication styles.
Impersonation setup. A spoofed email address or WhatsApp account is created using the CEO's or CFO's name and, often, their profile photo scraped from LinkedIn.
The urgent request arrives. A finance executive receives a message marked "CONFIDENTIAL — Urgent" that requests an immediate UPI transfer to a newly added beneficiary. The message explicitly discourages calling to verify, citing sensitivity or the executive being "in a meeting."
Psychological pressure is applied. The message implies serious business consequences — a deal falling through, a penalty, or a compliance deadline — if the transfer is delayed. Timing is deliberate: peak business hours or public holidays when the real executive is hard to reach.
Transfer is made. The employee, trusting the sender's apparent identity, initiates a UPI transfer via their company banking app. The amount often falls just under internal approval thresholds to avoid scrutiny.
Funds disappear instantly. The money is withdrawn in cash or routed through multiple accounts within minutes, making recovery extremely difficult.
Real Warning Signs (What to Watch For)
- An "executive" email or WhatsApp message you weren't expecting, marked confidential
- Request specifically says do not call or do not discuss with others
- A new or unfamiliar UPI ID or beneficiary added just before the request
- Message arrives on a Friday afternoon, long weekend, or public holiday
- Unusual urgency language: "transfer must happen in the next 30 minutes"
- The sender's email domain looks slightly off (e.g.,
@company-india.comvs@company.com) - WhatsApp profile photo matches your real CEO but the number is unknown
What Happens to Victims
UPI transactions are near-irreversible once processed — NPCI's dispute window is narrow, and most fraudulent transfers are swept into cash within minutes of arrival, making bank-level freezes unlikely to succeed unless reported within the hour. Victims face not just financial loss but professional consequences: employees who approved fraudulent transfers sometimes face internal disciplinary action, adding emotional distress to financial damage.
For businesses, the aftermath involves RBI grievance filings, police FIRs, and potential forensic audits — all of which take time and legal resources. Victims are strongly advised to consult a qualified legal professional for case-specific guidance on liability and recovery.
What RBI, CERT-In, and I4C Say
CERT-In (cert-in.org.in) regularly issues advisories warning Indian organisations about Business Email Compromise and social-engineering attacks targeting finance teams. Their published guidance consistently emphasises out-of-band verification — confirming any financial request through a separate, known phone number before acting.
The RBI has directed banks and payment system operators to implement transaction monitoring flags for unusual beneficiary additions and high-value UPI transfers made outside normal business patterns.
I4C (Indian Cybercrime Coordination Centre) operates the 1930 cybercrime helpline, which handles financial fraud reports and can coordinate with banks to flag and attempt to freeze fraudulent transactions. Filing on cybercrime.gov.in creates an official record essential for insurance claims and legal proceedings.
How to Protect Yourself
- Always verify verbally. Call the executive directly on their known, saved number before processing any urgent transfer — regardless of what the message says.
- Check the sender's domain carefully. One misplaced character in an email address is a red flag.
- Never use contact details provided in the suspicious message itself to "verify."
- Establish a company policy: no UPI transfer above a set threshold without dual approval and a voice confirmation.
- Treat "do not call" instructions as an automatic red flag — legitimate executives do not discourage verification.
- Cross-check new UPI beneficiaries with your finance team before initiating any first-time payment.
- Report suspicious UPI IDs to BharatSecure.app so they can be flagged in the threat-intelligence database.
What to Do If You've Been Targeted
- Call 1930 immediately — the National Cybercrime Helpline. Speed is critical; early reports have the best chance of triggering a bank-level hold.
- File a complaint at cybercrime.gov.in — you will receive a complaint ID for all follow-up.
- Contact your bank's fraud desk directly and request an urgent transaction dispute on the specific UPI transfer.
- Preserve all evidence — screenshots of the WhatsApp message or email, the UPI transaction ID, and the fraudulent UPI ID.
- Inform your organisation's IT/security team so internal systems can be reviewed for compromise.
- File an FIR at your nearest police station if the bank cannot reverse the funds.
Frequently Asked Questions
Can a UPI transfer ever be reversed after I've been scammed? UPI payments are designed to be instant and final. Reversal is possible only in rare circumstances — typically when the receiving account is frozen before the funds are withdrawn. Calling 1930 within the first hour gives you the best, though not guaranteed, chance of a hold being placed.
How do fraudsters get my CEO's name, photo, and communication style so accurately? In reported cases, fraudsters gather this information entirely from public sources — LinkedIn profiles, company websites, press releases, and social media. No hacking is required. This is why limiting the amount of internal hierarchy information visible publicly is a recommended precaution.
My company uses WhatsApp for internal communication. Is that a problem? WhatsApp's informal nature makes it a preferred channel for this type of impersonation in reported cases. A fraudster can create a profile with your boss's name and photo in minutes. Any financial instruction arriving via WhatsApp — no matter how legitimate it appears — should always be confirmed by a separate voice call to the real person's known number.
Should the employee who made the transfer be held responsible? This is a legal question specific to employment contracts and company policy — consult a qualified lawyer for advice on your situation. What is clear from reported patterns is that these scams are deliberately designed to exploit trust and time pressure; the manipulation is sophisticated. That said, organisations benefit from having written SOPs that protect employees by making dual-authorisation mandatory.
Suspect a message is fake? Scan it instantly at BharatSecure.app and report financial fraud to the 1930 helpline — every report helps protect the next potential victim.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- Confinement and Forced Scam Labour Abroad — Severity: CRITICAL
- Thailand Transit to Cyber Trafficking Scam — Severity: CRITICAL
- Kidnapping Threat With AI-Cloned Voice — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.