SEBI Warns: Rising ‘Boss Scam’ Cyber Fraud

SEBI WARNS AGAINST THE RISING ‘BOSS SCAM’ CYBER FRAUD

Why in the News?

  • Regulatory Advisory: The Securities and Exchange Board of India (SEBI) has issued an advisory to regulated entities and listed companies warning them about the rising incidence of the ‘Boss Scam’, a sophisticated cyber fraud.
  • AI-Driven Threat: Acting on inputs from the Indian Cyber Crime Coordination Centre (I4C), SEBI has urged organisations to strengthen verification mechanisms against frauds using artificial intelligence (AI), deepfakes, and malware.

SEBI Warns: Rising ‘Boss Scam’ Cyber Fraud

WHAT IS THE ‘BOSS SCAM’?

  • Impersonation Fraud: The Boss Scam is a form of Business Email Compromise (BEC) in which cybercriminals impersonate a CEO, Managing Director, or other senior executive to trick employees into making unauthorised financial transfers.
  • Deepfake Technology: Fraudsters use AI-generated voice cloning, manipulated video calls, fake messaging accounts, and spoofed emails to convincingly imitate company leadership and create a sense of urgency.
  • Malware-Based Attacks: Criminals also distribute malicious ZIP files containing executable (.exe) and Dynamic Link Library (.dll) files that install malware, enabling unauthorised access to corporate systems.
  • Targeted Employees: Finance, accounts, treasury, and payment-authorisation officials are the primary targets, as they have access to company funds and financial systems.
  • SEBI’s Advisory: Organisations have been advised to strengthen multi-level verification procedures, employee awareness, cybersecurity practices, and authentication mechanisms before processing high-value transactions.

SIGNIFICANCE OF THE ISSUE

  • Emerging Cyber Threat: The increasing use of AI and deepfake technologies has made cyber frauds more convincing, difficult to detect, and capable of bypassing traditional security measures, reflecting broader patterns of strategic competition in the digital domain.
  • Financial Stability: Successful attacks can result in substantial financial losses, reputational damage, data breaches, and disruption of business operations, undermining economic interdependence and trust in digital financial systems.
  • Corporate Governance: Robust internal controls, segregation of duties, and verification protocols are essential components of good corporate governance and risk management.
  • Cyber Awareness: Regular employee training and cyber hygiene practices are critical to reducing human errors, which remain one of the weakest links in organisational cybersecurity.
  • Need for Coordination: Effective prevention requires multilateral engagement and regional security cooperation among SEBI, I4C, CERT-In, financial institutions, and corporate entities to strengthen India’s cyber resilience and support a cooperative security framework aligned with the indo-pacific strategy.

INDIAN CYBER CRIME COORDINATION CENTRE (I4C)

  About: The Indian Cyber Crime Coordination Centre (I4C) is an initiative of the Ministry of Home Affairs (MHA) established to provide a coordinated framework for combating cybercrime in India, contributing to the broader indo-pacific strategy for digital security.

  Objectives: It aims to prevent, detect, investigate, and prosecute cybercrimes, while strengthening coordination among law enforcement agencies, regulators, and other stakeholders through strategic partnerships and diplomatic engagement.

  Key Functions: I4C manages the National Cyber Crime Reporting Portal, provides cyber forensic support, develops threat intelligence, conducts capacity building, and promotes public awareness as part of India’s regional security architecture.

  Institutional Support: The Centre works closely with CERT-In, State Police Cyber Cells, financial institutions, and regulatory bodies to address emerging cyber threats and online financial frauds, recognizing the role of cybersecurity in the context of strategic competition between major powers including US and China.

  UPSC Relevance: Important for Prelims and GS Paper III (Internal Security & Cyber Security) covering cybercrime, digital governance, artificial intelligence, critical information infrastructure protection, and financial cybersecurity.