Rajasthan Police have arrested four people in connection with an alleged ₹6.80 crore "Boss Scam," a cyber fraud in which criminals allegedly hacked a company's computer system, impersonated its director, and tricked the accounts head into transferring money to three separate bank accounts. Police say ₹3.50 crore of the defrauded amount has since been placed on hold.
How the ₹6.80 Crore Fraud Allegedly Unfolded
According to police, cybercriminals targeted the private firm's computer system on August 26 using malware referred to as "Tarzan," allegedly gaining access to the company director's WhatsApp Web session through the AnyDesk remote-access application.
Once inside, the fraudsters reportedly created a replica of the director's chat history and saved a new number under his name, effectively cloning his identity within the messaging thread. Using that fabricated identity, they messaged the company's accounts head and convinced him to transfer ₹6.80 crore into three separate bank accounts. Police confirmed the transaction had not been authorised by any actual director at the company.
Who Has Been Arrested
Additional Director General of Police (Cyber Crime) V.K. Singh said the arrests followed a complaint filed by Sunil Joshi, the accounts head of the private limited firm, lodged through the National Cyber Crime Helpline 1930 and acted on by the State Cyber Crime Police Station. The four arrested suspects have been identified as Jaipur residents Mayank Kasotia and Brijmohan Dron, alias "Lucky," Samanaram of Deedwana-Kuchaman, and Moti Yadav of Sikar.
Following the Money
Initial investigation found the fraud proceeds were allegedly distributed through a familiar layering pattern: mule accounts, digital wallets, QR codes, and cryptocurrency, all designed to obscure the money trail as it moved further from its original source.
How Telegram and Crypto Reportedly Fit In
Police say the fraudsters monitored fund movements through a Telegram channel. Bank accounts, ATM cards, SIM cards, and passbook kits were allegedly purchased from individuals for between ₹10,000 and ₹15,000 each, essentially buying ready-made mule infrastructure rather than setting up fresh accounts themselves. The stolen money was transferred into these accounts before being moved onward, with alleged masterminds operating from Singapore and Hong Kong reportedly using internet banking to route funds further through various other accounts.
Kasotia allegedly provided his own bank account to receive the fraud proceeds. Once money landed there, he allegedly withdrew cash via cheque and handed it over to Ashish and Brijmohan, with some funds also reportedly moved through QR codes and digital wallets.
Brijmohan allegedly arranged bank accounts for the wider fraud network and facilitated transfers through mule accounts, reportedly using Telegram and Binance to convert the illicit funds into USDT (a cryptocurrency stablecoin) before forwarding them to the alleged mastermind. Investigators say Samanaram connected Brijmohan with the actual cryptocurrency transactions through Telegram, while Yadav allegedly helped arrange bank accounts, transfer money into mule accounts, facilitate cash withdrawals, and manage subsequent transfers, along with converting some of the funds into USDT himself.
Recovery Efforts Underway
Police say ₹3.50 crore of the ₹6.80 crore allegedly defrauded has been placed on hold, with efforts now underway to secure a refund for the affected company.
How Businesses Can Protect Themselves From Boss Scams
Cases like this highlight why companies should always independently verify unusual or high-value payment instructions before transferring funds, even when a message appears to come directly from a senior executive through a familiar chat thread. Employees should treat unexpected remote-access requests, sudden changes in a known contact's phone number, and urgent payment instructions with genuine caution, and should immediately report any suspected cyber fraud through official channels rather than acting first and questioning later.
FAQs
Q1. How did the fraudsters gain access to the director's identity?
They allegedly used malware called "Tarzan" to hack the company's system on August 26, gaining access to the director's WhatsApp Web session through AnyDesk, then created a replica chat history under a new number saved as his name.
Q2. How much money was allegedly transferred, and how much has been recovered?
₹6.80 crore was allegedly transferred to three bank accounts, of which ₹3.50 crore has been placed on hold, with efforts underway to secure a refund.
Q3. How was the stolen money reportedly moved and hidden?
Through mule accounts, digital wallets, QR codes, and cryptocurrency, with funds allegedly converted into USDT via Binance and routed through masterminds operating from Singapore and Hong Kong.
Q4. What should businesses do to protect against similar scams?
Independently verify any unusual or high-value payment instructions, even from apparent senior executives, treat unexpected remote-access requests or changed contact numbers with caution, and report suspected fraud immediately.