On July 13, a chief financial officer in Pune transferred ₹56 lakh to fraudsters after receiving a Microsoft Teams message that appeared to come from her company’s Italy-based CEO. The scheme unraveled the next day when a second demand for ₹1.5 crore prompted a direct phone call — and stopped a much larger loss.

According to a police report, the 49-year-old CFO was working from home when a Teams profile bearing the CEO’s name and photograph instructed her to urgently move funds for a government project. She complied. Only when a follow-up message the next morning sought another ₹1.5 crore did suspicion arise. A call to the real CEO confirmed the impersonation, and the Pimpri-Chinchwad Cyber Crime Police were alerted.

The incident is the latest in a string of “boss scams” targeting Pune-based companies, but it carries a distinct lesson for millions of Microsoft Teams users: the platform’s familiar interface can be weaponized to bypass scepticism that email might trigger.

The fraud unfolded over two days

The first message came on July 13, claiming the CEO was tied up with an urgent government project and needed ₹56 lakh sent to two accounts. The CFO, recognizing the executive’s photo and name inside Teams, processed the payment without a secondary check. The following morning, a second message demanding an additional ₹1.5 crore pushed the fraud into implausible territory. The CFO phoned the Italy-based CEO directly and discovered the entire conversation was a fabrication.

Police investigators are now tracing the fake Teams account and the destination bank accounts. Early indications suggest the attacker had done homework: the impersonator knew the CFO had payment authority, that the real CEO was overseas, and that an urgent cross‑border instruction would not seem unusual.

Why Microsoft Teams became the perfect trap

For years, organizations have trained employees to distrust unexpected emails. Few have built the same reflexes around Teams chats. The platform carries what security researchers call a “trust halo” — employees see it as an authenticated, internal workspace where only colleagues can reach them.

That assumption is dangerous. An external Microsoft account can mimic a display name and profile picture just as easily in Teams as in email. The blue-and-white interface with a company logo does not guarantee identity. In this case, a photograph and a familiar name were enough to suspend normal verification.

Fraudsters exploit three psychological levers: authority (you don’t question the CEO), urgency (a fake government deadline), and secrecy (the request implied a confidential deal). Combined, they override the natural hesitation a finance professional would normally have. Remote work amplifies the effect — there’s no desk neighbour to tap on the shoulder.

Warning signs every Teams user must know

You don’t need to be a CFO to encounter a boss scam. Anyone with access to sensitive data, payment systems, or even just internal directories can be a target. Here’s what should set off alarms:

  • A message from a senior executive you rarely interact with directly.
  • A request to transfer money, change bank details, buy gift cards, or share sensitive files.
  • Pressure to act immediately without following standard approval steps.
  • Instructions to keep the request confidential or bypass normal channels.
  • A profile that looks correct but shows an “External” tag — or none at all when you expect one.

The Pune CFO later told police that the second, larger demand felt off. That instinct, followed by a phone call to a known number, saved the company from a ₹1.5 crore loss. The rule is simple: if an executive asks for money or data, verify through a different channel.

Locking down Teams: a checklist for IT administrators

The scam does not require a compromised account — the attacker may simply use an external Teams account with a copied display name. IT teams should review their tenant configuration immediately:

  • Restrict external access: Use allow lists for trusted domains and block communication with unmanaged accounts unless there is a clear business reason.
  • Train users to spot external indicators: Microsoft Teams can show warnings or labels for external contacts, but employees must know where to look. Screenshots from your own tenant are far more effective than generic advice.
  • Enforce phishing-resistant MFA: Push notifications can be defeated. Deploy Windows Hello for Business, FIDO2 security keys, or certificate-based authentication for privileged financial users.
  • Activate Conditional Access policies: Require compliant devices, trusted locations, and sign-in risk assessments for anyone with payment authority.
  • Monitor impossible travel and unfamiliar sign-ins: A login from a new country followed immediately by a request for money should trigger an automatic lock and investigation.
  • Enable Microsoft’s anti-phishing features for Teams: The platform can flag suspicious external chats. Verify these protections are turned on and that your security team receives alerts.

Rewiring payment controls for the messaging age

The core failure in Pune was not the CFO’s gullibility — it was a process that allowed a single chat message to initiate an irreversible transfer. Companies must assume that any communication channel can be forged and build controls accordingly.

  • Never complete a high-value payment based on a chat or email alone. The request must be entered into a formal workflow with an audit trail.
  • Validate new beneficiaries independently. A callback to a known, stored number is still one of the strongest defences. Do not use contact details supplied in the suspicious message.
  • Require dual approval. A second authorised person should review the business purpose and documents before funds are released.
  • Set transaction limits based on role, geography, and business need. An unexpected ₹56 lakh transfer should trigger automated alerts.
  • Eliminate the “CEO exception.” Employees must know they will never be punished for pausing a payment to verify. If the CEO routinely demands bypasses, the culture is the vulnerability.

How we got here: a pattern of CEO fraud in Pune

The Pune region hosts multinational engineering, pharma, and technology subsidiaries. Overseas executives, distributed finance teams, and cross-border payments create a fertile environment for impersonation scams. Since 2022, local police have registered over two dozen whale‑phishing cases. In 2022, fraudsters posed as a Serum Institute of India executive and walked away with ₹1 crore. A 2024 attack on a real estate company netted ₹4 crore.

The Indian Cyber Crime Coordination Centre (I4C) and the Securities and Exchange Board of India (SEBI) have both issued warnings. SEBI told listed companies to shore up verification procedures specifically because attackers now use WhatsApp, Microsoft Teams, and social media alongside email.

What you can do right now

If you manage a Microsoft 365 environment, don’t wait for an incident to happen.

  • Audit Teams external access today. Identify which domains actually need connectivity and block the rest.
  • Run a simulation: Send a test impersonation message from a controlled external account to a handful of finance employees and see who reports it.
  • Update your incident response plan to include Teams as a potential vector. Know how to quickly block an external account, revoke sessions, and contact your bank’s fraud team.
  • Tell your team one rule: If you’re asked to move money or share sensitive data, stop and verify using a known phone number. No exceptions.

If you’re an everyday Windows user, the lesson is simpler: a face and a name on a screen prove nothing. Treat every urgent request with suspicion and pick up the phone.

Outlook: AI, deepfakes, and the next wave

Generative AI will make impersonation even harder to detect. Attackers can already clone a voice from a few seconds of audio, and synthetic video is improving fast. Imagine a Teams call where the person on screen looks and sounds exactly like your CEO, claiming a connection problem and asking for a quick transfer.

Defences must evolve beyond visual and auditory trust. Payment systems will need to treat every digital communication as untrusted by default, relying instead on cryptographic identity proofs, transaction context, and multi‑person approvals. Microsoft continues to improve Teams’ external user protections, but technology alone won’t fix a culture where urgency beats verification.

The Pune case proves that one telephone call can stop a ₹1.5 crore fraud. The challenge for every organization using Microsoft 365 is to make that call mandatory before the money moves.