A sugar trader based in Pune experienced a significant loss of Rs three crore due to a sophisticated whale-phishing attack that occurred within a mere hour on Monday. According to police reports, cybercriminals compromised the trader’s accountant’s phone, manipulated the messaging system to make it seem as though the trader was sending the messages, and subsequently orchestrated three unauthorized money transfers from the company’s bank account.
The incident was documented in a First Information Report (FIR) filed at the Pune City Cyber Police Station on Monday, detailing that the fraud unfolded swiftly on the morning of August 31. The victim, a 42-year-old sugar trader operating a family-run business in Market Yard, informed authorities that his accountant, who has been employed with the firm for nearly nine years, received a WhatsApp message from an unfamiliar number that was saved under the trader’s name around 10:47 AM. This message inquired about the firm’s internet banking balance, to which the accountant replied, stating that the account held approximately Rs 8.50 crore.
Shortly afterward, the accountant received a message containing the details of a Bank of Baroda account, along with a request to “transfer 3 Cr.” Mistakenly believing these messages were genuine and coming from the trader, the accountant utilized the company’s accounting software to execute three transfers of Rs one crore each. Investigations later revealed that these funds were sent to mule accounts located in Rewa districts of Madhya Pradesh.
The fraudulent activity came to light when the trader received a call from the accountant requesting a GST number associated with the transaction. The trader clarified that he had not authorized any such transfer or instructed anyone to move funds. Upon examining the accountant’s computer, it was confirmed that Rs three crore had indeed been transferred to the beneficiary account in three separate transactions.
Additionally, the trader scrutinized the accountant’s mobile device and discovered that his own name had been used to save the WhatsApp number from which the instructions had originated. However, both the WhatsApp number and the conversation had vanished from the device.
During further inquiry, the accountant mentioned that he had received a suspicious file titled “Transaction_Details_31/08/2026 img” from another unknown number two days prior. A second accountant in the firm had also received the same file. An officer involved in the investigation noted, “The probe indicates that this malware was employed to breach the accountant’s phone, access contacts, and facilitate the fraudulent activities.” A case has been registered under the Information Technology Act and related provisions of the Bharatiya Nyaya Sanhita concerning cheating and criminal conspiracy, with Police Inspector Sharad Shelke leading the investigation.
An official from the Cyber Police Station explained that whale phishing, often referred to as a boss scam or CEO scam, represents a highly specialized form of phishing where fraudsters specifically target high-ranking executives, business owners, or individuals with access to substantial funds. Unlike traditional phishing schemes, this method involves a thorough analysis of the victim’s communication habits to craft messages that appear authentic. In typical whale-phishing scenarios, perpetrators may contact the victim from an unknown number, impersonating a CEO using their name and photograph. However, in this more invasive approach, attackers gain access to existing devices or accounts, utilizing the victim’s messages and continuing conversations in a manner that resembles prior communication patterns and contexts.
Cyber police officials advise organizations to exercise caution when processing payment instructions received via messaging applications. They recommend that any requests involving significant fund transfers or changes to beneficiary accounts should be independently verified through a phone call to a known and previously authenticated number. Companies should routinely review active WhatsApp Web sessions, implement multi-factor authentication, restrict the installation of unverified software, and perform periodic cybersecurity audits. Additionally, finance teams are encouraged to adopt dual-approval systems for high-value transactions and engage in ongoing training to recognize signs of phishing and account breaches.




















