HDFC Bank alerts customers to the increasing threat of ‘Boss Scam’ frauds, where cybercriminals impersonate senior officials to manipulate staff into making unauthorised payments, underscoring the need for heightened vigilance and robust verification measures.
HDFC Bank has warned customers to watch for “Boss Scam” fraud, a form of impersonation attack in which criminals pose as senior executives or trusted colleagues to pressure staff into making payments or handing over sensitive information. According to the bank, the scheme is designed to create urgency and exploit workplace hierarchy, with finance and accounts teams often the main targets.
The tactic usually begins with a message or email that appears to come from a regulator or company leader, such as a chief executive or another senior officer. The fraudster may claim there has been a compliance breach and attach a ZIP file purporting to contain documents. Once opened, the file can install malware, which may let attackers gain control of the executive’s device and access their messaging accounts. From there, they can send apparently legitimate transfer instructions, sometimes even storing their own number under the executive’s name on the compromised device to make the request look genuine.
The warning from HDFC Bank echoes broader alerts from regulators and cybersecurity firms. The Federal Trade Commission has also cautioned about boss imposter scams, while the Securities and Exchange Board of India has warned listed companies and regulated entities about fraudsters posing as CEOs, managing directors and other senior officials to push unauthorised fund transfers. McAfee describes the fraud as a form of spear phishing, a targeted attempt to trick specific people into revealing information or moving money.
Manish Agrawal, senior executive vice president for credit intelligence and control at HDFC Bank, said awareness is the strongest defence and urged organisations to maintain tight controls over software installation, staff training and payment verification. The bank advised people to confirm any urgent transfer request through a direct phone call or face-to-face check, avoid opening unknown ZIP or executable files and report suspicious activity through India’s cybercrime helpline, the Chakshu portal or the National Cyber Crime Reporting Portal. It also said victims should immediately alert their bank so payment channels such as cards, UPI and net banking can be blocked to limit further losses.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





