The Microsoft Teams Directors Scam: How a Mumbai Company Was Targeted for ₹2.3 Crore
A Mumbai company was reportedly targeted in a ₹2.3 crore “boss scam” after fraudsters impersonated directors inside a fake Microsoft Teams chat. Learn how the attack worked and how Indian businesses can stop payment fraud before money leaves the bank.
A professional-looking Teams chat can feel trustworthy. That is exactly what makes Microsoft Teams impersonation scams dangerous.
In a reported Mumbai cyber-fraud case, scammers allegedly created a fake Microsoft Teams group, impersonated two company directors, and persuaded a senior finance executive to initiate an RTGS transfer of ₹2.3 crore. The payment was later questioned during transaction review, and the company contacted cyber police. According to reports, authorities were able to block the funds before the scammers withdrew them.
This was not a technical hack involving malware or a stolen password. It was a social-engineering attack: criminals used familiar names, a credible workplace platform, a fake business conversation, urgency, and authority to make an unusual payment request look legitimate.
For Indian SMEs, finance teams, CA firms, and procurement departments, the lesson is simple:
Never approve or release a high-value payment solely because a request appears in Microsoft Teams, WhatsApp, email, or any other chat platform.
What Happened in the Reported Mumbai Case?
The reported incident took place on July 31, 2026. A senior finance executive of an industrial company was added to a Microsoft Teams group named “work group.” The chat reportedly included accounts using the names of two company directors.
Before the finance executive joined, the scammers had allegedly created a realistic-looking conversation about a business contract. This made the group appear active and genuine.
One of the impersonated “directors” then asked about the company’s bank balance. After receiving that information, the scammer instructed the finance executive to transfer ₹2.3 crore to a rubber company in West Bengal and shared bank account details.
The finance executive reportedly asked a subordinate to process the payment through RTGS. A copy of the transaction confirmation was then shared back into the fake Teams group.
The fraud was discovered only after another employee reviewing the day’s bank transactions questioned the large transfer.
When the team independently contacted the real directors outside Microsoft Teams, they discovered that the directors had not created the group or approved the payment.
he company promptly contacted cyber police, and reports state that the beneficiary account was blocked before the money could be withdrawn.
Why This Scam Worked
The attack succeeded because the fraudsters did not send an obviously suspicious message. They copied the normal environment in which employees already trusted their leaders.
1. Microsoft Teams looked like an internal workplace channel
Many organisations use Microsoft Teams daily for meetings, approvals, documents, and management communication. A payment request inside Teams may therefore appear more genuine than a message from an unknown WhatsApp number.
But a familiar platform does not prove that a profile is authentic.
2. The fraudsters impersonated senior leadership
The attackers allegedly used the names of two real directors. In a workplace, employees are trained to respond quickly to senior leaders, especially when a message relates to a contract, vendor, deadline, or confidential financial matter.
This is called a boss scam, CEO fraud, or whale phishing attack.
3. The chat was prepared in advance
The fake conversation reportedly included discussion about a business contract before the finance executive was added. This “conversation seeding” made the request appear like the final step of an ongoing internal decision, rather than a sudden request from a stranger.
4. The payment was treated as routine
The scam involved RTGS, a legitimate bank-transfer method. There was no suspicious attachment, no unknown software, and no obvious fake website. The attackers convinced authorised employees to make the payment themselves.
5. Verification happened after the transfer
An independent call to the real directors exposed the scam. However, it happened only after the RTGS instruction had already been sent.
The key control failed: out-of-band verification before payment.
What Is a Microsoft Teams Boss Scam?
A Microsoft Teams boss scam is a targeted fraud in which criminals impersonate a CEO, managing director, finance head, vendor, or other trusted executive on Microsoft Teams.
The attacker may use:
- A display name matching a real director or manager
- A profile photograph copied from LinkedIn, the company website, or social media
- A convincing job title
- A fake Teams chat or external account
- A pre-written discussion that looks like an active business conversation
- Urgent instructions to transfer funds
- A new bank account or beneficiary details
- Requests for secrecy or quick action
The target is usually a person who can initiate, approve, or influence payments: a CFO, finance manager, accounts executive, procurement lead, executive assistant, or business owner.
These attacks are not limited to Mumbai. In a separate reported case, a Pune engineering company lost ₹30 lakh after an alleged fraudster impersonated one of its directors on Microsoft Teams and instructed an employee to transfer money.
7 Red Flags in a Microsoft Teams Payment Request
A Teams message is not a valid payment approval by itself. Treat the following signals as high risk.
1. A new or unexpected Teams group
Be cautious if you are suddenly added to a new group called “Work Group,” “Management,” “Urgent Project,” “Confidential,” or something similar.
A real director may communicate through Teams, but an unexpected group involving money should always be independently verified.
2. A request to share the company bank balance
Senior leaders may need financial information, but a request for available balances inside an unusual chat should trigger an escalation.
Do not share banking details, account balances, OTPs, payment limits, or treasury information until you verify the requester through an official channel.
3. Urgent payment instructions
Fraudsters use urgency to stop people from thinking clearly.
Watch for phrases such as:
- “Transfer this immediately.”
- “This is confidential.”
- “Do not delay.”
- “The vendor is waiting.”
- “I am in a meeting; don’t call.”
- “Handle this personally.”
- “We will explain later.”
Urgency is not proof of legitimacy.
4. A new beneficiary or changed bank account
A request to pay a new vendor, update an existing supplier’s bank details, or send funds to an unfamiliar entity needs additional controls.
Never rely on bank details received only through Teams, WhatsApp, SMS, or email.
5. The sender has the right name but an unfamiliar identity
A display name and profile image can be copied. Ask:
- Is this person an internal employee, guest, or external user?
- Does the account use the approved company domain?
- Is the Teams profile new or unfamiliar?
- Does the contact card show an unexpected email address or organisation?
Check the actual account identity—not only the name or photograph.
6. The request bypasses normal approval processes
If a director’s message asks you to skip finance approvals, ignore the purchase order process, avoid calling the vendor, or process a transfer without documentation, stop immediately.
Legitimate leaders should support controls that protect the company.
7. You are told not to call or verify
This is one of the strongest warning signs.
A genuine director will not object if you independently verify a large payment using their known office number, company mobile number, or an in-person conversation.
The “Verify Before You Pay” Rule
Every business should adopt one non-negotiable rule:
No high-value or unusual payment can be approved solely through a chat message.
Before paying, the finance team should independently verify the instruction using a trusted channel that the sender did not provide in the suspicious message.
For example:
- Receive a payment request on Microsoft Teams.
- Do not reply with bank details or payment confirmation.
- Call the director using the official number saved in the company directory.
- Confirm the beneficiary name, amount, bank account, purpose, and payment deadline.
- Obtain a second approval from an authorised person.
- Record the verification in the payment file.
- Only then release the payment.
Do not use a phone number, email address, link, or meeting invite included in the suspicious request. Use only a known, verified contact method.
How Indian SMEs Can Prevent CEO Fraud
You do not need an enterprise-sized security budget to prevent most boss scams. You need clear payment controls and a team culture that supports verification.
Create a two-person approval process
Require at least two authorised people to approve high-value transfers, new beneficiaries, and changed bank details.
For example:
- Finance executive initiates the payment.
- Finance manager or director approves it.
- A separate person verifies the beneficiary details.
- The bank transfer is released only after all approvals are recorded.
Set payment thresholds
Define clear rules based on transaction value.
For example:
- Payments above ₹50,000 require manager approval.
- Payments above ₹2 lakh require independent phone verification.
- Payments above ₹10 lakh require two senior approvers and a documented callback.
- Any new bank beneficiary requires verification regardless of amount.
Your exact thresholds should match your business size and payment patterns.
Use a trusted callback procedure
Maintain a verified internal directory with the official phone numbers of directors, finance heads, vendors, and key approval authorities.
When a payment request is unusual, call the person using this directory—not a number received through chat.
Verify supplier bank changes independently
Supplier bank-account change requests are a common business-email-compromise tactic.
Confirm changes by calling a known contact at the supplier company and asking them to verify:
- Legal company name
- Account-holder name
- Bank name
- Account number
- IFSC code
- Reason for the change
- Invoice or purchase-order reference
Restrict external Microsoft Teams access
Review your Microsoft Teams settings and reduce unnecessary access.
Your IT administrator should consider:
- Restricting external access to approved partner domains
- Reviewing guest users regularly
- Removing inactive guest accounts
- Enabling multi-factor authentication for all employees
- Training staff to identify external or guest profiles
- Monitoring unusual group creation and external invitations
- Retaining Teams, sign-in, and audit logs for investigations
The Indian Express reported that investigators advised companies to restrict external Teams access where possible, review guest and external users, enable multi-factor authentication, and use second-level approval for large or unusual payments.
Train finance and procurement teams
Your employees are not the weak link. They are the last line of defence when a scam reaches a real payment workflow.
Train them to pause when they see:
- Urgency
- Secrecy
- New beneficiary details
- Requests to bypass policy
- Senior-leader impersonation
- Sudden changes in payment process
- Messages received only through chat
Employees should never be punished for verifying a senior person’s request. Make “verify before you pay” part of your culture.
A Simple Teams Payment Verification Checklist
Use this checklist before approving a payment requested through Microsoft Teams.
- Is the request expected and supported by a purchase order, contract, or invoice?
- Is the Teams account confirmed as the real employee or director?
- Is the sender an external user or guest?
- Is the beneficiary new or has the bank account changed?
- Has the request been confirmed by calling the requester’s known official number?
- Has the payment been approved by a second authorised person?
- Has the beneficiary been verified independently?
- Is there written documentation of the business purpose?
- Does the request use urgency, secrecy, or pressure?
- Would you still make this payment if the request came from a normal employee instead of a director?
If any answer raises doubt, stop the payment and escalate it.
What to Do If Your Company Has Already Paid
If you suspect your business has made a fraudulent transfer, speed matters.
- Contact your bank immediately and request a hold, recall, or freeze on the transaction.
- Call India’s cyber-fraud helpline at 1930 as soon as possible.
- File a complaint through the National Cyber Crime Reporting Portal.
- Inform local cyber police and preserve all evidence.
- Save screenshots of Teams messages, participant profiles, chat names, payment instructions, beneficiary details, invoices, and transaction confirmations.
- Preserve Microsoft Teams audit logs, email logs, login records, and bank records.
- Change passwords and review access if there is any chance that a real account was compromised.
- Notify affected directors, finance staff, and IT/security teams.
- Review why existing payment controls did not stop the transfer.
- Update your approval and verification processes immediately.
Fast action can make a major difference. In the reported Mumbai incident, prompt reporting reportedly helped police block the money in the beneficiary account before withdrawal.
How ScamShield AI Helps Finance Teams
ScamShield AI helps Indian businesses identify fraud signals in suspicious business messages, payment instructions, links, documents, screenshots, and communication content.
For a possible Microsoft Teams boss scam, finance teams can use ScamShield AI to review:
- Suspicious payment instructions
- Lookalike sender names and business identities
- Fraud language, urgency, and authority-pressure signals
- Unusual beneficiary details
- Payment screenshots and transaction confirmations
- Vendor documents and GST-related information
- Suspicious URLs, QR codes, and attachments
ScamShield AI should support—not replace—your company’s payment controls. The strongest protection is a combination of AI-assisted fraud detection, trained staff, independent verification, and two-person approval.
Frequently Asked Questions
Can someone impersonate a director on Microsoft Teams?
Yes. A fraudster may create an account or profile using a real director’s name, photo, and job title. A familiar display name does not prove the sender is genuine. Always verify high-risk requests through an official, independent channel.
Is Microsoft Teams safe for payment approvals?
Microsoft Teams is useful for communication, but it should not be the only channel used to approve high-value payments, new beneficiaries, or changed bank details. Use documented financial controls and independent verification.
What is a boss scam?
A boss scam, also known as CEO fraud or whale phishing, is a targeted impersonation attack in which criminals pretend to be senior executives and direct employees to transfer money, share sensitive information, or change payment details.
How can I verify a Teams payment request?
Call the requester on a phone number already saved in your official company directory. Confirm the amount, purpose, beneficiary, and bank details. Do not use a number or link sent in the suspicious Teams chat.
What should I do after a fraudulent RTGS transfer?
Contact your bank immediately, call 1930, report the incident to the National Cyber Crime Reporting Portal, preserve evidence, and notify cyber police. Acting quickly gives you the best chance of freezing the beneficiary account.
Final Takeaway
The Mumbai Microsoft Teams case shows that fraud no longer arrives only through suspicious emails or unknown WhatsApp messages. Attackers are now using trusted workplace tools to make fake instructions look like real business decisions.
A Teams profile can be copied. A director’s name can be copied. A group chat can be staged. A payment request can look completely professional.
But one control can stop many of these scams:
Verify every unusual or high-value payment through a separate, trusted channel before money leaves the bank.
If a payment instruction feels urgent, confidential, or unusual, pause. Verify. Then pay.