What happened here
A company accounts head reportedly sent ₹6.80 crore to three accounts after messages impersonating a director. Police announced a 12th arrest on 26 September.
The payment request appeared to come from inside the company
Rajasthan police say an accounts head at a Jaipur company received WhatsApp instructions that appeared to come from a director. Investigators allege the offenders gained access to a company computer or messaging session, changed the apparent contact identity and recreated earlier chat context. The record reviewed here does not establish every technical step independently.
Transfers and discovery
On 24 August 2026, the firm reportedly transferred ₹6.80 crore to three bank accounts. The company later confirmed that its directors had not authorised the payments and reported the fraud on 25 August. The reported amount is the value transferred, not a confirmed final loss or recovery total.
The investigation continued
Early September reporting described six arrests. Police later said the number had risen to 12 after a further arrest announced on 26 September. Those arrested are accused, not convicted. Investigators describe supporting bank accounts and movement of funds, but the public record does not establish how much money has ultimately been returned to the company.
Where the control failed
The request was treated as an instruction from a trusted senior person within a familiar chat thread. A high-value payment required a second, independent authorisation channel and beneficiary verification. Even a familiar profile, old message history or apparent urgency cannot replace a call to a known number and a documented approval.
If your organisation notices a false instruction
Stop further transfers, call the bank’s official fraud contact, preserve chats and payment references, and report immediately to 1930 and cybercrime.gov.in. Have a separate incident lead check account access and tell staff which messages are no longer trustworthy. Do not publicly name uninvolved employees or promise recovery before the bank confirms it.
- Suspects allegedly gained access to messaging context and created an apparent director identity
- Accounts head reportedly transferred ₹6.80 crore to three accounts
- Company complained after directors denied authorising payments
- Police reported initial arrests, later reaching six and then eight
- Police announced a 12th arrest and continued tracing the network
Why consequences escalated
- The apparent trusted sender and recreated chat history made the instruction persuasive.
- A messaging account or profile is not independent proof of authority.
- A second channel to a known number could have interrupted the payment.
- Three beneficiary accounts were reported for the transfers.
- The announced arrest count changed as the investigation progressed.
- Transfer amount, held funds and money returned are distinct measurements.
Failures and risk multipliers
- Approving a large transfer solely from a chat instruction.
- Using a number supplied in the suspicious message to verify it.
- Skipping beneficiary-account checks because the request looks urgent.
- Treating a familiar profile photo or prior conversation as authentication.
- Failing to report the transfer promptly to the bank and 1930.
People closest to the evidence
“I4C and SEBI warn that senior-executive impersonation can arrive over messaging and direct subordinates to transfer funds”
SEBI press release 40/2026 · General advisory, not a finding about this accused group · Source ↗
Actions that reduce risk
- Require two-person approval for high-value or new-beneficiary payments.
- Confirm urgent executive requests by calling a previously verified number.
- Separate payment creation from release authority.
- Review active linked messaging sessions and device access.
- Train staff to pause confidential or time-pressured payment requests.
- Contact the bank and 1930 immediately if a payment was sent.
- Document actual funds held and returned separately.

Leave a comment