A rice mill company in Ahmedabad lost Rs 80 lakh after a sophisticated hacker compromised an accountant's phone and impersonated the company owner via a contact swap.
- Hacker used a malicious file to gain unauthorized access to the accountant's device.
- The attacker replaced the owner's actual phone number with his own in the contact list.
- Rs 80 lakh was fraudulently transferred before the scam was detected.
In a daring instance of cyber fraud in Ahmedabad, a rice mill company fell victim to a highly calculated attack that resulted in a loss of Rs 80 lakh. The scammer did not just impersonate the boss; they literally replaced the boss's identity within the victim's own phone.
The victim, an accountant named Jayeshbhai, was targeted via a malicious file sent to his mobile device. Once the file was executed, the hacker gained full administrative access to the phone. In a strategic move, the attacker navigated to the contacts app and swapped the phone number of the company owner, Pradeepbhai, with his own, while keeping the same display name and profile picture.
Believing the messages were coming from his employer, Jayeshbhai followed instructions sent via WhatsApp to transfer Rs 80 lakh to a designated bank account. The seamless nature of the deception ensured that the accountant did not suspect any foul play during the initial transaction.
Why This Matters
BozokMedia analysis shows that this incident represents an evolution in social engineering. By manipulating the device's local database (the contact list), the scammer bypassed the psychological barriers that usually trigger when a user sees an unknown number. This 'Internal Trust Breach' is far more effective than standard phishing, as it leverages existing professional hierarchies and trust.
"The most dangerous vulnerability in any corporate structure is not the software, but the misplaced trust in a digital identity that hasn't been verified via a second channel."
The fraud only came to light when the scammer grew greedy and demanded an additional Rs 30 lakh. This second request triggered a red flag for the accountant, who then approached Pradeepbhai in person, leading to the discovery of the heist.
This case is a textbook example of a "Boss Scam," where fraudsters impersonate C-suite executives to manipulate subordinates. The Ahmedabad Cyber Crime Department is currently analyzing the digital trail to identify the perpetrator.
Frequently Asked Questions
1. What is a 'Boss Scam'?
It is a form of Business Email Compromise (BEC) or social engineering where attackers pose as senior executives to trick employees into making unauthorized payments.
2. How can companies prevent such frauds?
Implement a mandatory 'dual-authorization' policy for all corporate transfers, requiring a voice call or physical signature regardless of the digital request.