Menu

A Fake CEO’s WhatsApp Message Drained Rs 10.4 Crore, and Gold Hid the Trail

Fraudsters hijacked a Mumbai CEO’s WhatsApp to steal Rs 10.4 crore in 63 transfers, then laundered nearly half of it into gold to dodge investigators.

Ishan Crawford 20 hours ago 0 2

Girish Amin, a deputy general manager at a Mumbai firm, wired Rs 10.40 crore (roughly $1.2 million) out of company accounts in 63 transfers over less than two weeks. He believed every instruction came from his boss on WhatsApp. It did not.

Police eventually traced the money and clawed back close to half of it. The other half went into gold jewellery, pledged and re-pledged with local moneylenders until the digital trail simply stopped. Investigators are now seeing that same laundering trick surface again elsewhere, which is the part of this story that outlasts one company’s bad week.

A ‘Personal Number’ from the Boss

Amin is not a novice. He has spent more than three decades at his company, a firm with offices across India. So when a message arrived on June 3 from an unfamiliar number carrying his boss’s photo as the display picture, he had little reason to doubt it.

The sender’s name field read Sidharth Jain, the company’s executive director. The fraudster told Amin to save the number as a “very personal number” and not to share it with anyone, framing it as Jain’s alternate line. It is not unusual for senior executives to keep separate personal and official numbers, which is exactly what made the lie land.

When the first payment request came through, Jain was supposedly walking into a meeting and could not take a call. Amin transferred Rs 46,50,102 on that instruction alone. Over the days that followed, more WhatsApp messages arrived with fresh beneficiary accounts attached.

  1. June 3: An unknown number, showing Sidharth Jain’s photo and name, contacts Amin and asks him to save it as a private line.
  2. June 3 to June 15: Amin acts on a string of WhatsApp instructions, moving money across 63 transactions.
  3. June 16: Amin asks the real Jain, through an official channel, for invoices tied to the transfers. The impersonation falls apart.
  4. June 22: The Indian Cyber Crime Coordination Centre (I4C) issues a nationwide advisory on the pattern it calls the “Boss Scam.”

When Mumbai police first called Amin to say he might be a fraud victim, he did not believe them either. Officers said that made sense, since fraudsters running “digital arrest” scams routinely pose as police to frighten victims into compliance. It took official identification before Amin accepted that the second call was the real one.

The Zip File That Hijacked a CEO’s Phone

The scam did not start with Amin. It started with Jain, or rather with software pretending to come from a regulator.

According to the I4C advisory, cybercriminals approach chief executives and senior officials through email or WhatsApp, posing as bodies such as the Reserve Bank of India and citing an urgent compliance issue. The message carries a compressed archive. Investigators say the fraudsters first phone a company’s office landline under the pretext of confirming an IFSC code, a trick that hands them the direct number of whoever handles the firm’s banking.

Inside the archive sits a malicious executable paired with a Dynamic Link Library file. Once opened on a Windows device, it launches what the advisory calls a Trojan dropper. From there, the malware compromises the executive’s Windows device and active Web WhatsApp sessions, enabling the fraudsters to message subordinate employees and orchestrate fraudulent financial transfers, exactly as it did in Jain’s name. In some versions of the scam, attackers go further, quietly editing the phone’s contact list so their own number is saved under the boss’s name. The government has already moved against related infrastructure elsewhere: I4C has blocked 83,668 WhatsApp accounts tied to cyber fraud, alongside thousands of Skype IDs.

Why Was the Man Approving Transfers Also the Victim?

Indian companies typically split fund transfers into two roles, a creator who initiates a request and an approver who has to clear it before money moves. In Amin’s case, both jobs belonged to the same person. Once the fake boss had fooled the creator, no second set of eyes was left to catch the fraud.

  • Creator-approver system – an internal control where one employee files a payment request and a separate, senior employee must verify and authorise it before funds are released, designed so a single compromised employee cannot move company money alone.

Investigators found that Amin held both designations for these particular transfers, which is precisely why sixty three separate payments went out without a single internal flag. The money reached 40 accounts spread across 30 cities in 10 states before anyone inside the company questioned it.

Gold Becomes the Exit Ramp for Stolen Crores

Most cyber fraud proceeds move through a chain of mule bank accounts to blur their origin. This case used mule accounts too, but only as a first stop.

Field operatives then used the funds sitting in those accounts to buy high value gold ornaments from established jewellery chains across Maharashtra, Uttar Pradesh, West Bengal and Bihar. The gold was pledged to local moneylenders for cash loans. That “clean cash” was routed through a fresh set of untainted accounts back to the syndicate’s leadership. When money from a separate cyber offence arrived later, it was used to redeem the pledged gold from one shop, only for that same gold to be pledged again elsewhere.

When law enforcement agencies track the digital money, the trail leads them to a jewellery shop. But this is where the link goes cold. It becomes incredibly difficult to track where that physical gold was subsequently mortgaged to extract cash.

An investigating officer described the technique to The Indian Express, which first reported Amin’s case. Cybercrime researchers elsewhere have flagged the identical pattern: proceeds routed through layered accounts before conversion into gold or other assets that are simple to store, move and resell, breaking the digital trail that investigators normally rely on.

Two Playbooks for Cleaning Stolen Crores

Gold is not the only escape route Indian cyber syndicates have engineered this year. Just days ago, the Enforcement Directorate unveiled a separate racket that laundered far more money, using cryptocurrency instead of jewellery.

Case Amount Laundered Laundering Method Arrests Recovered or Frozen
Mumbai Boss Scam (Amin case) Rs 10.40 crore Gold bought through jewellery chains, pledged and re-pledged to moneylenders 6 Nearly 50% put on hold
ED Dubai crypto ring Rs 303 crore 216 mule accounts layered into USDT, Ethereum and Solana via exchanges, moved toward Dubai linked wallets 10 arrested, 45 accused overall Rs 8.69 crore in bank balances attached, crypto seized

The Enforcement Directorate said its probe identified 216 mule bank accounts moving Rs 303 crore before funds reached foreign controlled crypto wallets. Crypto still leaves a blockchain ledger that investigators can eventually subpoena from an exchange. Gold, once melted or resold through an unlicensed moneylender, generally does not.

Mumbai Beat India’s Recovery Average, and Still Lost Half

Zoom out to the national numbers and Amin’s case looks unusual for the right reason. Indians lost at least Rs 22,495 crore to cyber fraud in 2025, and the national recovery rate improved to just 24% that year. Three out of four rupees stolen through cyber fraud in India are never seen again. I4C’s own broader projection puts total 2025 losses, including unreported cases, closer to Rs 1.2 lakh crore.

Mumbai police recovering close to 50% of Amin’s stolen crores is roughly double that national average. Multi state coordination among Mumbai, Delhi and investigators chasing suspects into Bihar moved fast enough to freeze a meaningful share before it vanished into gold.

Yet the other half is likely gone for good, precisely because of the conversion technique. Since 2021, the Citizen Financial Cyber Fraud Reporting and Management System has saved over Rs 8,189 crore across more than 23.61 lakh complaints, almost entirely by freezing digital accounts fast. That system has nothing to freeze once stolen rupees have become a gold bangle sitting in a moneylender’s vault.

The Same Lucknow Numbers Keep Resurfacing

An officer investigating Amin’s case said some of the phone numbers involved had already surfaced once before, in a similar scam carried out in February, both traced to Lucknow in Uttar Pradesh. That detail suggests a working syndicate refining a playbook rather than a one off crime.

Amin’s company is also not the only one to be hit this way. A separate incident reported by The Print described an executive named Pravin losing Rs 1.5 crore after fraudsters gained access to his accountant’s computer through WhatsApp Web, the same entry point used against Jain’s identity.

WhatsApp sits at the center of nearly every version of this fraud because it is the default channel for real business communication across Indian offices, not a side channel companies can simply switch off; the platform’s every change draws regulatory attention in India, including a recent extension India granted Meta on a WhatsApp username feature. Six people have been arrested so far in Amin’s case, from Delhi to Jalna in Maharashtra to Samastipur in Bihar. Investigators still do not know who runs the syndicate, and they are still chasing the rest of the missing crores.

Frequently Asked Questions

What makes the ‘boss scam’ different from older CEO email fraud?

Older CEO fraud, known as business email compromise, relied on spoofed addresses or lookalike WhatsApp profiles that trained staff could sometimes catch through odd domains or spelling mistakes. The boss scam instead hijacks the executive’s genuine WhatsApp account through malware, so messages arrive from a real, already trusted number.

What is the ‘golden hour’ investigators mention in cyber fraud cases?

It is the first hour after a fraudulent transfer, when banks and payment gateways still have the best chance of freezing funds before criminals scatter them across mule accounts. Reporting to the 1930 helpline inside that window sharply raises recovery odds; waiting even a day lets stolen money move several layers deep.

How much money has India’s Suspect Registry blocked before it even moved?

Banks have shared more than 26.48 lakh suspect Layer 1 mule accounts with the registry, which has helped decline transactions worth more than Rs 9,055 crore, according to figures the home ministry gave Parliament.

What should an employee do before acting on a boss’s payment request?

I4C’s advisory tells finance staff to verify any urgent transfer or bank detail change through a direct phone call or an in person conversation, never on the strength of a WhatsApp message alone, and to check regularly which devices are logged into the company’s WhatsApp Web sessions.

Why do fraud syndicates prefer gold over crypto or cash for laundering?

Gold can be bought with cash sitting in mule accounts and then pledged to local moneylenders for fresh, untainted money, with no exchange KYC or blockchain ledger for investigators to pull. Once melted down or resold, it leaves no transaction record at all, which is why officers say the trail simply stops at the jewellery counter.

Written By

Prior to the position, Ishan was senior vice president, strategy & development for Cumbernauld-media Company since April 2013. He joined the Company in 2004 and has served in several corporate developments, business development and strategic planning roles for three chief executives. During that time, he helped transform the Company from a traditional U.S. media conglomerate into a global digital subscription service, unified by the journalism and brand of Cumbernauld-media.

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *