A Pune-based engineering company fell victim to a high-stakes 'whale phishing' attack where a fraudster impersonated a director on Microsoft Teams to siphon off Rs 30 lakh.

  • A Pune engineering firm lost Rs 30 lakh to a cybercriminal impersonating a director on Microsoft Teams.
  • The attacker successfully infiltrated the company's internal Teams group using a fake profile.
  • The fraud is classified as 'Whale Phishing' or a 'Boss Scam.'
  • Police have launched an investigation at Bhosari MIDC police station.

Pune: In a startling escalation of corporate cybercrime, a Pune-based engineering company has been defrauded of Rs 30 lakh. The perpetrator utilized Microsoft Teams, a standard workplace communication tool, to execute a highly targeted 'whale phishing' attack by impersonating one of the company's directors.

According to the FIR filed at the Bhosari MIDC police station, the fraudster created a profile complete with the director's name and photograph. This allowed the attacker to seamlessly join the company's internal Microsoft Teams group. Once inside, the impersonator sent a direct instruction to an employee, ordering an urgent transfer of Rs 30 lakh to a specified bank account. The deception was only uncovered after the transaction was completed and the real director was contacted.

Why This Matters

BozokMedia analysis shows that the shift from mass email phishing to platform-specific impersonation marks a dangerous trend in cyber warfare. By operating within Microsoft Teams, criminals exploit the inherent trust employees place in their internal communication channels. Unlike a random WhatsApp message, a directive appearing within a professional workspace carries a veneer of legitimacy that can bypass standard skepticism.

Unlike conventional Whale phishing communication on WhatsApp or email, a fraudulent message appearing in a familiar corporate communication environment can make employees less suspicious.

This incident mirrors a recent case involving an Italian engineering company's CFO in Pune, who was targeted by a fake CEO profile seeking Rs 56 lakh. In that instance, manual verification saved the firm, highlighting the critical need for secondary authentication protocols during financial transactions.

Historical Background

'Whale Phishing,' also known as CEO fraud, has become a significant threat to global enterprises. The Securities and Exchange Board of India (SEBI) and the Indian Cyber Crime Coordination Centre (I4C) have issued multiple alerts regarding these scams. Criminals are increasingly moving away from blunt-force attacks toward highly researched, social-engineering-based tactics that target specific high-value individuals within an organization.

Did You Know?: Whale phishing is specifically designed to target 'big fish'—high-level executives or employees with significant financial authority.

Frequently Asked Questions

Question 1: How can employees identify a 'Boss Scam'?
Answer: Employees should look for unusual urgency, requests for secrecy, or instructions to bypass standard financial protocols, even if the message comes from a known profile.

Question 2: What technical measures can companies implement?
Answer: Organizations should enforce multi-factor authentication (MFA), restrict external access to Teams, and mandate a 'call-back' verification for all large transfers.