A suspected cyber fraud involving the impersonation of a university president on WhatsApp has led to the arrest of four people in Bengaluru. Investigators allege that the accused used a senior official’s identity to persuade an accountant to transfer ₹1.40 crore from the institution’s bank account.
According to the case details reported by The420.in, police recovered ₹8.50 lakh in cash and seized four mobile phones during the investigation. Authorities are examining the alleged money trail and searching for another suspect who remains absconding.
The incident highlights the financial risks organisations face when payment instructions are accepted through messaging apps without independent verification.
How the WhatsApp Impersonation Allegedly Took Place
The case came to light after an employee of a deemed-to-be university filed a complaint with the police on September 9. The complaint stated that an unauthorised transaction had taken place the previous day.
According to the report, the university accountant received a WhatsApp message from an unknown person using the photograph of university president Dr Chennaraj Roychand. The sender allegedly asked about the institution’s bank balance before instructing the accountant to transfer ₹1.40 crore.
Believing the request was genuine, the accountant reportedly followed the instructions. The transfer later became the focus of a cybercrime investigation.
Police are investigating how the perpetrators obtained information about the institution and whether the impersonation was part of a wider, coordinated operation.
What Is a WhatsApp Boss Scam?
A boss scam, also known as business impersonation fraud, occurs when criminals pretend to be a company owner, senior executive or other trusted authority figure to persuade an employee to make a payment or reveal confidential information.
Fraudsters may use a familiar display photograph, a convincing name and an urgent request to make a message appear authentic. The approach can be particularly effective when employees are accustomed to following instructions from senior management.
The Bengaluru case illustrates why identity verification must be separate from the messaging platform through which a request is received.
Suspicious Files and Financial Monitoring Under Investigation
Investigators reportedly found that a ZIP file had been sent to members of the institution. Police suspect that the file may have played a role in the alleged compromise of institutional information.
The investigation also indicated that the suspects may have monitored the university’s financial activity for approximately 15 to 20 days before the disputed transfer. Authorities are examining digital evidence, transaction records and reported connections involving foreign IP addresses.
These details remain part of the investigation, and the precise method used to obtain access to the institution’s information will need to be established through evidence.
Four Arrested as Police Trace the Money Trail
Police have arrested four suspects identified in the report as Annayya, Rupasali Ravikumar Reddy, Ambaraya and Syed Wajihuddin Quadri.
Investigators suspect that different individuals had separate roles in arranging bank accounts, receiving funds and handling withdrawals. The report also names a suspect known as Sunny, alias David, who is allegedly absconding.
According to the reported findings, some of the money was moved through multiple accounts before being withdrawn. Police are continuing to investigate the financial transactions and the alleged involvement of each suspect.
The arrests are part of an ongoing investigation; allegations against the accused have not, by themselves, established guilt.
Police Recover Cash and Mobile Phones
During the operation, authorities reportedly recovered ₹8.50 lakh in cash and seized four mobile phones. The cash was said to be linked to another online fraud investigation in Aurangabad, Maharashtra.
Police are analysing the digital devices and financial records to understand how the alleged fraud was organised and whether other individuals or accounts were involved.
The case was investigated by Karnataka Cyber Command and the South Division Cyber Crime Police Station, according to the supplied report.
How Organisations Can Prevent WhatsApp Payment Fraud
The incident offers several practical lessons for businesses, universities and other institutions handling substantial financial transactions:
- Verify payment requests independently: Confirm unusual instructions through a known phone number or an established internal communication channel.
- Require dual authorisation: Large transfers should require approval from at least two authorised individuals.
- Avoid relying on profile photographs: A familiar name or image does not prove the sender’s identity.
- Treat unexpected files with caution: Do not open unknown attachments or follow suspicious links on work devices.
- Protect financial information: Restrict access to bank details, payment records and sensitive institutional data.
- Report fraud quickly: In India, victims can contact the national cybercrime helpline at 1930 and report incidents through the official cybercrime reporting portal.
Organisations can also strengthen their financial controls through regular reviews and auditing services in India, helping identify weaknesses in payment authorisation and recordkeeping procedures.
The Bigger Lesson: Verify Before You Transfer
The alleged ₹1.40 crore Bengaluru fraud demonstrates how digital impersonation can exploit workplace trust and routine financial processes. Even when a message appears to come from a senior official, employees should never rely on a messaging app alone to authorise a significant transfer.
For organisations, the strongest safeguards combine independent identity checks, clearly defined payment approval procedures, employee awareness and prompt reporting of suspicious activity.