Overview
- SEBI issued a formal advisory after I4C flagged a rise in CEO and MD impersonation fraud, with the advisory circulated to listed companies and regulated entities on July 17, 2026.
- One method uses AI tools such as voice cloning and deepfake video calls to make fake instructions from senior executives sound and look authentic.
- A second method sends malicious .zip files that install a Trojan dropper on Windows machines and can steal active WhatsApp Web session tokens so attackers send payment orders from genuine accounts.
- Attackers may alter compromised devices’ contact lists or create fake groups and they often pressure staff by citing unpublished price-sensitive information to block verification.
- SEBI urged immediate steps including independent verbal verification of payment requests, not opening unverified executables, logging out of unused WhatsApp Web sessions, and reporting incidents to the national cybercrime helpline 1930.