A Mumbai-based company has reported the transfer of ₹2.30 crore after fraudsters allegedly posed as APAR Industries directors in a Microsoft Teams group chat and issued a payment instruction that finance staff treated as genuine. The Free Press Journal, citing the FIR filed with Mumbai’s South Cyber Police Station, reports that the transfer was initiated on July 31 and flagged only during a later review of the day’s transactions.
The incident is a costly example of a control failure that Windows and Microsoft 365 administrators cannot solve solely with stronger Teams settings: an attacker did not need to deploy malware, take over a workstation, or bypass an RTGS banking control. According to the police complaint described by the Free Press Journal, the attackers persuaded authorized employees to perform the payment themselves.
APAR Industries’ own corporate disclosures identify Kushal N. Desai as chairman and managing director and Chaitanya N. Desai as managing director, matching the executives allegedly impersonated in the chat. The company’s March 2026 governance filing also lists Vinayak K. Lele as senior vice president of finance and a member of its risk-management committee, corroborating the organizational roles described in the complaint. That is important context: this was not a random “CEO fraud” message sent to a junior employee. The alleged attackers selected the people and relationships needed to make a high-value payment look procedurally normal.
No public statement from APAR Industries, Mumbai Police, Bandhan Bank, or Microsoft was located independently confirming the ₹2.30 crore loss, the recipient account, or whether any funds were frozen or recovered. Those details therefore remain allegations in the FIR as reported by the Free Press Journal, rather than established findings from the investigation.
The reported sequence is unusually revealing. The Free Press Journal says Lele was added at about 2:55 p.m. to a Teams group called “Work Group,” which appeared to contain accounts using the names and Teams identities of both Desai brothers. Before Lele joined, the attackers had apparently seeded the chat with a discussion about a business contract.
That preloaded conversation is the key tactic. A direct message ordering a ₹2.30 crore transfer should prompt suspicion; an executive request appearing at the end of an ongoing conversation between two real company leaders can instead look like an operational decision that the finance department merely has to execute. The fraudulent group chat became a substitute for a verbal approval trail.
The apparent Kushal Desai account then asked for the company’s bank balance, according to the report, and directed Lele to transfer ₹23 million to an entity called MB Rubber in West Bengal. The beneficiary banking details, reportedly at Bandhan Bank, were posted in the chat. Lele then instructed senior manager Parameswaran Mahadev Ayyar to process the RTGS payment, and the transfer confirmation was allegedly returned to the Teams group at the attacker’s request.
This is business email compromise without the email. The attack works because collaboration platforms inherit the authority workers ordinarily assign to the people and work threads inside them. Once the message reaches the payment approver with a convincing enough identity, a bank’s authentication mechanisms validate that an authorized customer ordered a payment—not that the business purpose behind it was legitimate.
Microsoft’s own documentation recognizes impersonation and phishing as risks in external Teams chats. Its guidance tells users to inspect the sender’s identity, including email address, and to accept external conversations only when the sender is trustworthy. Microsoft also tells users receiving an unexpected or urgent request involving money to verify it through a separate, trusted channel. The alleged APAR case shows why these instructions need to be treated as payment-control requirements rather than generic awareness advice.
The reported answer was no. When the officials contacted Kushal Desai outside Teams, he denied creating the group or authorizing the transfer. That out-of-band check exposed the deception, but only after the RTGS instruction had been sent.
The practical lesson is sharper than “verify suspicious messages.” A finance team must have a mandatory verification path for every new beneficiary, material payment, or change to payment instructions, even when the request is shown in a familiar Teams thread and appears to come from an executive. The transaction should not be released until the approver contacts the executive using a known phone number, an existing verified chat, or another independent channel.
An approval path built around the same chat the attacker controls is not independent verification. Asking the alleged executive to confirm the payment in the Teams group, requesting a reply from the same account, or accepting a Teams-supplied callback number simply gives the attacker another opportunity to ratify their own instruction.
For many organizations, the appropriate rule is a two-person, two-channel control: one employee validates the commercial basis for a new payment, while another independently verifies the executive request using pre-established contact information. The second check must happen before the bank release, not as part of reconciliation afterward.
Those scenarios are very different for incident responders.
If the accounts were actually compromised, APAR would need to treat the episode as a broader Microsoft Entra ID and Microsoft 365 identity incident: revoke sessions, reset credentials, inspect multifactor-authentication changes, search sign-in and audit logs, review OAuth consents, examine mailbox and Teams activity, and assess whether the attackers accessed other company data.
If the attackers instead used external accounts or lookalike identities, the core failure may lie in Teams’ cross-tenant or consumer-account communication policies and in weak user recognition of external identity labels. Microsoft Teams supports chats with users outside an organization when external access is enabled, and external users can be permitted or blocked at the tenant level. A name and familiar display image are not evidence that the account belongs to the named executive.
Microsoft’s 2026 threat research has separately documented attackers using external Teams communications to impersonate IT or help-desk workers. Those campaigns often aim to gain remote access through Quick Assist or comparable tools, then deepen the compromise with legitimate administrative utilities. The APAR incident, as alleged, took a shorter route: it converted trust in Teams directly into an authorized payment.
That distinction changes the response priority. Endpoint telemetry and EDR may find nothing when the victim’s employee enters a legitimate bank transfer. The useful evidence is likely to sit in Teams message records, Entra sign-in logs, external-access configuration, Conditional Access events, recipient-account tracing, bank communications, and the approval records surrounding the transfer.
SEBI’s warning was explicit that organizations should strengthen internal controls and independently verify such requests. The regulator did not describe this as a theoretical phishing risk; it identified a payment-fraud method already reaching listed companies through the same communication tools used for routine work.
APAR Industries is listed, and its governance reports show a formal risk-management structure. The public record does not establish what controls APAR had in place at the time of the alleged fraud or whether any rule was bypassed. But the reported facts point to a gap that many enterprises share: approving an RTGS transfer may require the right internal banking authority while still lacking a reliable test that the underlying executive instruction is authentic.
That gap cannot be closed by pushing a security-awareness email after the fact. It requires a payment policy that treats a Teams message—whether it appears internal, external, or comes from an executive account—as insufficient authorization for a new or exceptional beneficiary.
The immediate measures are straightforward:
APAR Industries’ own corporate disclosures identify Kushal N. Desai as chairman and managing director and Chaitanya N. Desai as managing director, matching the executives allegedly impersonated in the chat. The company’s March 2026 governance filing also lists Vinayak K. Lele as senior vice president of finance and a member of its risk-management committee, corroborating the organizational roles described in the complaint. That is important context: this was not a random “CEO fraud” message sent to a junior employee. The alleged attackers selected the people and relationships needed to make a high-value payment look procedurally normal.
No public statement from APAR Industries, Mumbai Police, Bandhan Bank, or Microsoft was located independently confirming the ₹2.30 crore loss, the recipient account, or whether any funds were frozen or recovered. Those details therefore remain allegations in the FIR as reported by the Free Press Journal, rather than established findings from the investigation.
The Teams chat reportedly supplied the missing social proof
The reported sequence is unusually revealing. The Free Press Journal says Lele was added at about 2:55 p.m. to a Teams group called “Work Group,” which appeared to contain accounts using the names and Teams identities of both Desai brothers. Before Lele joined, the attackers had apparently seeded the chat with a discussion about a business contract.That preloaded conversation is the key tactic. A direct message ordering a ₹2.30 crore transfer should prompt suspicion; an executive request appearing at the end of an ongoing conversation between two real company leaders can instead look like an operational decision that the finance department merely has to execute. The fraudulent group chat became a substitute for a verbal approval trail.
The apparent Kushal Desai account then asked for the company’s bank balance, according to the report, and directed Lele to transfer ₹23 million to an entity called MB Rubber in West Bengal. The beneficiary banking details, reportedly at Bandhan Bank, were posted in the chat. Lele then instructed senior manager Parameswaran Mahadev Ayyar to process the RTGS payment, and the transfer confirmation was allegedly returned to the Teams group at the attacker’s request.
This is business email compromise without the email. The attack works because collaboration platforms inherit the authority workers ordinarily assign to the people and work threads inside them. Once the message reaches the payment approver with a convincing enough identity, a bank’s authentication mechanisms validate that an authorized customer ordered a payment—not that the business purpose behind it was legitimate.
Microsoft’s own documentation recognizes impersonation and phishing as risks in external Teams chats. Its guidance tells users to inspect the sender’s identity, including email address, and to accept external conversations only when the sender is trustworthy. Microsoft also tells users receiving an unexpected or urgent request involving money to verify it through a separate, trusted channel. The alleged APAR case shows why these instructions need to be treated as payment-control requirements rather than generic awareness advice.
The fraud was caught by a review, not a Teams warning
According to the FIR account, the transfer was discovered later on July 31 when Arpan Shah reviewed the day’s transactions and questioned the unusually large payment. The payee was not a regular business associate, which led to the decisive question: had Lele spoken directly with Kushal Desai?The reported answer was no. When the officials contacted Kushal Desai outside Teams, he denied creating the group or authorizing the transfer. That out-of-band check exposed the deception, but only after the RTGS instruction had been sent.
The practical lesson is sharper than “verify suspicious messages.” A finance team must have a mandatory verification path for every new beneficiary, material payment, or change to payment instructions, even when the request is shown in a familiar Teams thread and appears to come from an executive. The transaction should not be released until the approver contacts the executive using a known phone number, an existing verified chat, or another independent channel.
An approval path built around the same chat the attacker controls is not independent verification. Asking the alleged executive to confirm the payment in the Teams group, requesting a reply from the same account, or accepting a Teams-supplied callback number simply gives the attacker another opportunity to ratify their own instruction.
For many organizations, the appropriate rule is a two-person, two-channel control: one employee validates the commercial basis for a new payment, while another independently verifies the executive request using pre-established contact information. The second check must happen before the bank release, not as part of reconciliation afterward.
Teams identity is not the same thing as executive identity
The most consequential unanswered technical detail is how the alleged impostors came to appear as the company’s directors. The reporting says they used what looked like genuine Teams IDs, but it does not establish whether the attackers compromised corporate Microsoft 365 accounts, created lookalike unmanaged Microsoft accounts, exploited Teams external access, or used some other identity configuration.Those scenarios are very different for incident responders.
If the accounts were actually compromised, APAR would need to treat the episode as a broader Microsoft Entra ID and Microsoft 365 identity incident: revoke sessions, reset credentials, inspect multifactor-authentication changes, search sign-in and audit logs, review OAuth consents, examine mailbox and Teams activity, and assess whether the attackers accessed other company data.
If the attackers instead used external accounts or lookalike identities, the core failure may lie in Teams’ cross-tenant or consumer-account communication policies and in weak user recognition of external identity labels. Microsoft Teams supports chats with users outside an organization when external access is enabled, and external users can be permitted or blocked at the tenant level. A name and familiar display image are not evidence that the account belongs to the named executive.
Microsoft’s 2026 threat research has separately documented attackers using external Teams communications to impersonate IT or help-desk workers. Those campaigns often aim to gain remote access through Quick Assist or comparable tools, then deepen the compromise with legitimate administrative utilities. The APAR incident, as alleged, took a shorter route: it converted trust in Teams directly into an authorized payment.
That distinction changes the response priority. Endpoint telemetry and EDR may find nothing when the victim’s employee enters a legitimate bank transfer. The useful evidence is likely to sit in Teams message records, Entra sign-in logs, external-access configuration, Conditional Access events, recipient-account tracing, bank communications, and the approval records surrounding the transfer.
The regulator had warned listed companies weeks earlier
The reported July 31 transfer came two weeks after the Securities and Exchange Board of India issued a July 17 warning to regulated entities and listed companies about “Boss Scam” fraud. SEBI said it had been alerted by the Indian Cyber Crime Coordination Centre to schemes in which criminals impersonate CEOs, managing directors, senior executives, or trusted colleagues using email, WhatsApp, Microsoft Teams, and other platforms to direct fund transfers.SEBI’s warning was explicit that organizations should strengthen internal controls and independently verify such requests. The regulator did not describe this as a theoretical phishing risk; it identified a payment-fraud method already reaching listed companies through the same communication tools used for routine work.
APAR Industries is listed, and its governance reports show a formal risk-management structure. The public record does not establish what controls APAR had in place at the time of the alleged fraud or whether any rule was bypassed. But the reported facts point to a gap that many enterprises share: approving an RTGS transfer may require the right internal banking authority while still lacking a reliable test that the underlying executive instruction is authentic.
That gap cannot be closed by pushing a security-awareness email after the fact. It requires a payment policy that treats a Teams message—whether it appears internal, external, or comes from an executive account—as insufficient authorization for a new or exceptional beneficiary.
What Microsoft 365 administrators should change now
Teams administrators should start by inventorying every route through which people outside the tenant can reach finance, treasury, procurement, executive-assistant, and senior-management staff. External access may be operationally necessary, but “needed by some employees” is not a reason to leave it broadly open for every user handling payments.The immediate measures are straightforward:
- Restrict Teams external access to approved partner domains where the business can support an allowlist model, and disable unnecessary communication with unmanaged Microsoft accounts.
- Make external identity status visible in user training and ensure finance staff know where to inspect the actual account address and organization rather than relying on a display name, avatar, or conversation history.
- Define monetary thresholds and beneficiary-change conditions that require direct, recorded confirmation through a separate trusted route.
- Block payment approval based only on chat messages, including messages from accounts belonging to executives, until the required out-of-band confirmation is attached to the transaction record.
- Ensure Teams and Entra audit logging is retained long enough to support a financial-fraud investigation, and test whether the security team can retrieve membership, message, sign-in, and external-access evidence quickly.
- Give staff a clear escalation route for suspected payment impersonation, including immediate contact with the bank and India’s 1930 cybercrime helpline. India’s National Cyber Crime Portal specifically directs victims of cyber financial fraud to report promptly through 1930.
References
- Primary source: Free Press Journal
Published: 2026-08-06T15:05:46+00:00
Loading…
www.freepressjournal.in - Related coverage: support.microsoft.com
Prevent spam or phishing attempts from external chats in Microsoft Teams | Microsoft Support
Ensure your security from spam, phishing, or impersonation attempts from external chats in Microsoft Teams.support.microsoft.com - Related coverage: support.microsoft.com
Loading…
support.microsoft.com - Related coverage: learn.microsoft.com
Manage external bots and their access to meetings hosted in your organization - Microsoft Teams | Microsoft Learn
Learn how to configure the access that external bots get to Teams meetings hosted in your organizationlearn.microsoft.com - Related coverage: learn.microsoft.com
Security guide for Microsoft Teams overview - Microsoft Teams | Microsoft Learn
Security advice and learnings for IT admins in installing, configuring, and maintaining Microsoft Teams.learn.microsoft.com - Related coverage: microsoft.com
Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook | Microsoft Security Blog
Threat actors are abusing external Microsoft Teams collaboration to impersonate IT helpdesk staff and convince users to grant remote access. Once inside, attackers can abuse legitimate tools and standard admin protocols to move laterally and exfiltrate data while appearing as routine IT...www.microsoft.com - Related coverage: cdn-dynmedia-1.microsoft.com
Microsoft Incident Response - Cyberattack Series Part 3
cdn-dynmedia-1.microsoft.com
- Related coverage: cdn-dynmedia-1.microsoft.com
Loading…
cdn-dynmedia-1.microsoft.com - Related coverage: download.microsoft.com
Loading…
download.microsoft.com - Related coverage: news.microsoft.com
Loading…
news.microsoft.com - Related coverage: techcommunity.microsoft.com
Loading…
techcommunity.microsoft.com - Related coverage: microsoft.com
Help on the line: How a Microsoft Teams support call led to compromise | Microsoft Security Blog
Read the new Microsoft Cyberattack Series report to learn more about on how deception and trusted tools can enable identity-led intrusions.www.microsoft.com - Related coverage: expertinsights.com
Microsoft Teams Users Targeted in Fake IT Support Scam Linked to Black Basta Ransomware
Campaign abuses Microsoft Teams and Quick Assist to deploy previously undocumented backdoor.
expertinsights.com
- Related coverage: blogs.microsoft.com
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware - Microsoft On the Issues
Microsoft files legal case against Fox Tempest, a malware-signing service enabling cyberattacks by disguising malicious code as trusted software.blogs.microsoft.com - Related coverage: cyberproof.com
Microsoft Teams Vishing and Cross-Tenant Attack Chronicles: H1 2026 Analysis – CyberProof
Discover how threat actors abuse Microsoft Teams external access features for cross-tenant vishing attacks. Learn defensive mitigations and proactive threat hunting strategies from CyberProof's H1 2026 case studies.www.cyberproof.com
- Related coverage: techrepublic.com
Hackers Impersonate IT Help Desk on Microsoft Teams to Gain Access, Steal Data
Hackers are abusing Microsoft Teams chats to impersonate IT support, gain remote access, move laterally, and steal company data, Microsoft warns.www.techrepublic.com
- Related coverage: bleepingcomputer.com
Loading…
www.bleepingcomputer.com - Related coverage: taxguru.in
Loading…
taxguru.in - Related coverage: freepressjournal.in
Loading…
www.freepressjournal.in - Related coverage: csoonline.com
Attackers abuse Microsoft Teams to impersonate the IT helpdesk in a new enterprise intrusion playbook | CSO Online
Microsoft details a cross-tenant social engineering technique that tricks employees into granting remote access and enables stealthy data exfiltration.www.csoonline.com
- Related coverage: timesofindia.indiatimes.com
Loading…
timesofindia.indiatimes.com - Related coverage: cyberdefensemagazine.com
- Related coverage: sebi.gov.in
SEBI | Caution to Regulated entities and listed companies- Boss Scam
Securities and Exchange Board of India is made for protect the interests of investors in securities and to promote the development of, and to regulate the securities market and for matters connected therewith or incidental thereto
www.sebi.gov.in