Whale Phishing Scam: Pune Company Loses Rs 4 Crore in this Scam, Know about this new scam
A real estate company in Pune experienced a significant loss of Rs 4 crore due to falling victim to a Whale Phishing scam. This cybercrime targeted a senior executive within the company, leading to multiple unauthorized transfers to a fraudulent account.
Understanding Whale Phishing:
Whale Phishing, also known as CEO scam, specifically targets high-ranking individuals within organizations. It involves cybercriminals tricking executives into divulging sensitive information or making financial transactions under false pretenses.
How the Scam Unfolded:
Initial Contact: The scam began with the executive receiving messages from an unknown sender claiming to be the company’s Chairperson and Managing Director (CMD). The message requested urgent Real-Time Gross Settlement (RTGS) transfers to a specified account.
Gradual Escalation: Subsequently, the fraudsters continued to demand larger sums of money from the executive over several days, maintaining the guise of the CMD. The requests included providing bank account details and transferring increasing amounts, totaling Rs 4.06 crores across 18 transactions.
Realization of Fraud: The fraudulent nature of the transactions became apparent when the executive communicated with the real CMD, who confirmed not authorizing any such transfers. This realization prompted the filing of a complaint with Pune City police, leading to an FIR being registered.
Understanding Whale Phishing Tactics:
Research and Mimicry: Scammers conduct thorough research on their targets and organizations, using various online sources to gather information. They then craft convincing messages that emulate the style and tone of the individual they impersonate, urging urgent or confidential actions.
Common Requests: These messages typically involve requests for urgent actions, such as clicking malicious links, providing sensitive information, or approving financial transactions to fraudulent accounts.
Protecting Against Whale Phishing:
Vigilance: Exercise caution with unsolicited communications, verifying the sender’s identity through separate channels before taking action.
Avoidance of Suspicious Content: Refrain from clicking on suspicious links or opening attachments from unknown sources.
Awareness of Red Flags: Be wary of requests for urgent or confidential actions, as legitimate requests typically do not involve pressure or secrecy.
Reporting Suspicious Activity: Report any suspicious activity to the IT department or security team for further investigation.
By understanding the tactics employed by cybercriminals and remaining vigilant, individuals and organizations can mitigate the risks associated with Whale Phishing scams.