Mumbai Cybercrime Police Arrest Two in Bihar, Jharkhand in ₹48.60 Lakh Boss Scam

South Cyber Police trace fake WhatsApp CEO number to a SIM-card supply network, arrest two men and seize 161 SIM cards; investigators link them to at least seven similar fraud cases nationwide.

Mumbai Cybercrime Police Arrest Two in Bihar, Jharkhand in ₹48.60 Lakh Boss Scam

This Image is only for illustrations.

Mumbai Cybercrime Police have arrested two men from Bihar and Jharkhand in connection with a ₹48.60 lakh “Boss Scam”, in which fraudsters allegedly impersonated a company’s chief executive officer on WhatsApp and convinced an accountant to transfer money from a corporate account.

The South Cyber Police station arrested Aamir Chand Mohammad Khan, 22, an Airtel SIM distributor from Rukundipur in the Siwan district of Bihar, on August 14, 2026. His alleged associate, Suraj Kumar Pradeep Kumar Saw alias Vishal, 22, was arrested from Kumbhardhubi in Dhanbad district, Jharkhand, on August 16.

Investigators said the accused were allegedly connected to at least seven similar CEO-impersonation fraud cases reported across Mumbai, Punjab, Haryana, Delhi, West Bengal and Tamil Nadu.

Police have frozen the entire ₹48.60 lakh allegedly transferred in the Mumbai case and seized 161 Airtel SIM cards, a mobile phone, a SIM-activation handset and other equipment.


What Is a Boss Scam?

A “boss scam”, also known as CEO impersonation fraud, is a form of business email compromise or messaging-based cyber fraud. Criminals pretend to be senior company officials—such as CEOs, directors, CFOs or owners—and instruct employees to make urgent financial transfers.

The fraud usually depends on three things:

  • A convincing fake WhatsApp profile or hijacked account

  • Pressure and urgency, often framed as confidential business work

  • An employee with access to company bank accounts or payment systems

In this Mumbai case, the fraudsters allegedly used the photograph and identity of the complainant’s CEO to create a WhatsApp account. They then messaged the company accountant and instructed the employee to transfer funds to accounts controlled by the scammers. This story was also covered by The Hindu.

The term “Boss Scam” is effective because the message often appears to come from someone senior enough that an employee may hesitate to question it. The scammer may say that the deal is urgent, confidential, linked to a government filing, acquisition, vendor payment, tax compliance or regulatory issue.

The message is simple but powerful: “Do this now, don’t call, and keep it confidential.”

That combination is designed to bypass normal financial controls.


How the Mumbai Fraud Was Traced

The case was registered after a Mumbai-based company complained that its accountant had transferred ₹48.60 lakh after receiving WhatsApp instructions from a person impersonating the CEO.

The South Cyber Police carried out technical analysis of the WhatsApp number used by the fake CEO. Investigators traced the number to Rukundipur in Bihar’s Siwan district.

This led to the arrest of Aamir Chand Mohammad Khan, an Airtel SIM distributor, on August 14. Police alleged that Khan obtained or activated SIM cards through fraudulent documentation and wrong KYC details before supplying them to cybercriminals.

According to investigators, Khan allegedly sold eight SIM cards to Suraj Kumar Pradeep Kumar Saw alias Vishal for ₹6,000. Saw was then arrested in Jharkhand on August 16 following further technical investigation.

The police seized:

  • 161 Airtel SIM cards

  • A mobile phone

  • A megaphone

  • A Poco handset allegedly used for SIM activation

The recovery of 161 SIM cards indicates that the alleged network may have been operating at a scale far beyond a single CEO fraud case. SIM cards are a critical part of such operations because they help fraudsters create disposable WhatsApp accounts, receive OTPs and avoid linking scam communications to their real identities.


₹48.60 Lakh Frozen by Police

One major positive in the case is that Mumbai Cyber Police reportedly managed to freeze the entire ₹48.60 lakh allegedly transferred by the complainant.

In cybercrime cases, speed is everything. Money can move from one account to another within minutes, then be withdrawn, converted into cryptocurrency, transferred through mule accounts or layered through multiple beneficiaries.

The freezing of funds suggests that the complaint was reported quickly and that the police were able to trace the transaction before the amount was fully dissipated.

For victims of financial cyber fraud, this case underlines an important rule: report the incident immediately through the cybercrime helpline 1930 or the National Cyber Crime Reporting Portal.

The first few hours after a fraudulent transfer are often the best chance to block or freeze funds.


Police said the two accused were allegedly linked to seven similar cyber fraud cases. Of these, two cases were registered with the South Cyber Police Station in Mumbai. The remaining cases were reported in Punjab, Gurugram in Haryana, New Delhi, West Bengal and Tamil Nadu.

This interstate pattern is typical of organised cybercrime. One group may handle fake SIM cards and identity documents, another may create WhatsApp profiles, and another may communicate with victims, while separate operators manage bank accounts, cash withdrawals or digital transfers.

Such networks are difficult to dismantle because the people who talk to victims are often different from those who procure SIM cards, create bank accounts or receive the money.

The Mumbai case shows why police increasingly focus on the “enablers” of cybercrime—not only the person who sends the fake message, but also those who supply illegal SIM cards, false KYC details, mule accounts and technical infrastructure.


Indian Cyber Crime Coordination Centre Advisory

The Indian Cyber Crime Coordination Centre (I4C) issued an advisory on June 22, 2026, warning organisations about CEO impersonation fraud and malicious messages targeting senior executives.

According to the advisory, cybercriminals may send malicious archive files through email or WhatsApp, presenting them as urgent regulatory or compliance documents. Once a file is opened, malware can compromise an executive’s Windows device and active WhatsApp Web sessions.

This gives criminals access to communications and enables them to message subordinates from a seemingly legitimate executive account.

The danger is particularly high because employees may see:

  • A familiar profile picture

  • A familiar WhatsApp number or account context

  • Messages in the executive’s usual communication channel

  • References to genuine company work

  • Pressure to make immediate transfers

The I4C warning shows that a Boss Scam may not always involve a completely fake account. In more advanced cases, fraudsters may take over a real WhatsApp Web session or compromise a device, making detection harder.


Timeline

  • June 22, 2026: The Indian Cyber Crime Coordination Centre issues an advisory on CEO impersonation fraud, malicious archives and WhatsApp Web compromise.

  • Before August 2026: A Mumbai company accountant receives WhatsApp messages from a profile allegedly impersonating the company CEO.

  • Fraudulent transfer: The accountant transfers ₹48.60 lakh to accounts controlled by the alleged fraudsters.

  • Complaint lodged: The company reports the suspected Boss Scam to Mumbai’s South Cyber Police station.

  • Technical tracing: Police trace the fake CEO’s WhatsApp number to Rukundipur in Siwan, Bihar.

  • August 14, 2026: Aamir Chand Mohammad Khan, an Airtel SIM distributor, is arrested from Bihar.

  • August 16, 2026: Suraj Kumar Pradeep Kumar Saw alias Vishal is arrested from Jharkhand.

  • Evidence seized: Police recover 161 SIM cards, mobile devices and SIM-activation equipment.

  • Funds frozen: Mumbai Cyber Police freeze the entire ₹48.60 lakh allegedly transferred in the case.

  • Further inquiry: Investigators examine alleged links to seven similar fraud cases across multiple states.

Also Read: Fire Breaks Out at Mumbai’s Aayakar Bhavan in Churchgate; Evacuation Underway


Why This Matters

Yeh case kaafi important hai because Boss Scams target company money, exploit workplace hierarchy and can drain lakhs or crores from corporate accounts within minutes.

  • Corporate accounts are high-value targets: Unlike many individual scams, CEO fraud can involve large transfers from a single victim organisation.

  • Trust is weaponised: Fraudsters use a boss’s name, image and authority to make employees skip verification steps.

  • SIM-card misuse: The seizure of 161 SIM cards points to the importance of KYC compliance and monitoring of mobile connections.

  • Interstate network: The alleged links across seven cases show how cybercrime groups operate beyond city and state boundaries.

  • Fast reporting can save money: The full freezing of ₹48.60 lakh highlights the value of immediate cybercrime reporting.

For companies, the message is clear: no payment instruction—however urgent or senior it appears—should bypass a documented verification process.


India Angle

India’s rapid digitisation has made business payments faster, but it has also created new vulnerabilities.

Companies now use WhatsApp, email, UPI, online banking, vendor portals and cloud-based approval systems for everyday operations. These tools save time, but scammers exploit the same speed and informality.

CEO fraud is especially effective in India because many workplaces have hierarchical decision-making. An accountant or junior employee may feel uncomfortable calling a CEO directly to verify an urgent instruction.

Fraudsters know this. They often use language such as:

  • “I am in a meeting; do not call.”

  • “This is confidential.”

  • “Transfer immediately; approval is already in place.”

  • “Send the proof once done.”

  • “Do not involve anyone else.”

These are red flags.

Companies should adopt a mandatory “verify before pay” policy. Any request for a new beneficiary, unusual transaction, emergency transfer or deviation from normal procedure should require confirmation through an independent channel—such as a phone call to a known office number, video verification, signed email approval or dual-authorisation banking workflow.

“WhatsApp par boss ka message aaya” is not a valid payment authorisation.


The Mumbai case is not just about two arrests. It illustrates how a small technical vulnerability can combine with a human vulnerability.

A fake SIM card enables a fake or disposable WhatsApp account. A familiar CEO profile image creates trust. A rushed message bypasses normal approval. An employee’s fear of questioning a senior makes the fraud work.

Technology alone will not solve this. Companies need process discipline.

In my view, every organisation—whether a startup, SME, factory, school, hospital, NGO or large corporate—should treat WhatsApp payment instructions as unverified until independently confirmed.

The police action is significant because it targets alleged SIM suppliers, who are often the hidden backbone of fraud networks. But preventing future scams will require telecom compliance, stronger KYC, corporate awareness and fast reporting by victims.


What Next

The investigation is expected to continue on several fronts:

  • Tracing other fraud cases: Police will examine the alleged links to seven similar CEO fraud cases in multiple states.

  • SIM-card analysis: Investigators will review the 161 seized SIM cards, activation records, KYC documents, device data and linked WhatsApp accounts.

  • Bank-account trail: Police may trace beneficiary accounts, mule accounts, withdrawals and money movement linked to the ₹48.60 lakh transaction.

  • More arrests possible: The two arrested persons may lead investigators to account holders, WhatsApp operators, document suppliers and other members of the alleged network.

  • Telecom scrutiny: The case may trigger closer examination of SIM-point-of-sale agents, fraudulent KYC use and bulk SIM activation practices.

  • Corporate advisory: Companies may be urged to strengthen approval systems and train finance teams to identify CEO fraud attempts.


Conclusion

Mumbai Cyber Police’s arrest of two men from Bihar and Jharkhand in the ₹48.60 lakh Boss Scam case has exposed how CEO impersonation fraud can rely on fake WhatsApp identities, illegal SIM card supply and pressure tactics.

The seizure of 161 SIM cards and the alleged links to seven cases across India show that the fraud may be part of a wider interstate ecosystem.

The recovery of the entire defrauded amount is a rare and important relief for the victim company. But the case also serves as a warning for every business: no urgent payment message, even if it appears to be from the CEO, should be acted on without independent verification.

Written By A. Jack

Leave a Comment

Your email address will not be published. Required fields are marked *