Criminals use artificial intelligence to impersonate superiors over the phone or in video calls, pressuring employees into urgent transfers. The Indian financial regulator SEBI officially warned on July 17, 2026, about this scheme known as the “Boss Scam,” which, according to press reports, has also reached German companies. Anyone receiving such an instruction should call back on an independently verified phone number before making any payment.
Fraudsters Imitate Superiors with Cloned AI Voice
The scheme is known in professional circles as the “Boss Scam” and is not new, but artificial intelligence makes it significantly more convincing. Criminals copy the voice of a real executive from publicly available recordings, such as video interviews or conference recordings. With just a few seconds of audio material, a deceptively realistic artificial voice can be generated, which is hardly distinguishable from the real voice over the phone. In some cases, additionally, fake video images are used in calls via Teams or similar programs. For listeners, the artificial voice often sounds surprisingly natural, including the emphasis, throat clearing, and familiar word choice of the real person.
A second, widely used variant operates more technically. Fraudsters send a ZIP file disguised as an invoice or tax document via email or messenger. When the file is opened on a Windows computer, malware takes over the open WhatsApp Web session of the device. The fraudsters can then send messages from the real executive’s account, including an allegedly urgent payment instruction. Additionally, some attackers alter the saved contacts on the device so that a foreign number appears under the name of the boss.
How Daily Life in Accounting and Administration is Changing
Affected are primarily employees who can approve or execute payments: accounting, assistance, and administration. An example from practice: A clerk in the finance department receives a WhatsApp message from her CEO’s number asking her to immediately approve a confidential takeover payment. A quick callback using the number listed in the company directory reveals that the CEO never sent such a message; his account has been hijacked. Without this callback, the payment would have gone to a foreign account abroad.
Anyone receiving a similar instruction should proceed in this order:
- Do not execute the payment immediately, even if urgency or confidentiality is emphasized.
- Use the phone number listed in the company directory or on the business card, not the one from the message.
- Personally confirm the request over the phone.
- Involve a second person according to the four-eyes principle for unusual amounts.
- Report suspicious messages and calls to the IT department or security officer.
This order follows the SHS rule of police advice: Stop, Question, Protect.
Warning Applies Worldwide, Protective Measures Cost Nothing
The starting point of the current wave of warnings is a statement from the Indian financial regulator SEBI on July 17, 2026, which explicitly warns publicly traded and regulated companies about the scheme. According to SEBI, the warning was preceded by a report from the Indian Cyber Crime Coordination Center, which has registered an increase in corresponding fraud cases. The report itself is not a warning from German authorities; however, another report on the same wave of fraud explicitly mentions threatened companies in this country. The reports do not specify concrete damage amounts for Germany; the millions circulating internationally have not been independently verified.
Protection against the scheme costs nothing and does not require additional software. The police advice and the Federal Criminal Police Office provide their warning notices free of charge. The most important protective measure remains the telephone confirmation using an independently verified number, supplemented by a four-eyes principle for unusual payments and the regular logging out of unused WhatsApp Web sessions.
It remains open how many German companies have already been affected by the scheme, as there is currently no comparable reporting statistics in this country. It will be crucial whether companies consistently switch their payment approvals to the four-eyes principle, regardless of how convincing a voice or video image appears. Anyone discussing customer or company data in chat programs should also adhere to internal guidelines for handling confidential information, especially since hijacked accounts do not always become apparent immediately.


