A Mumbai-based company has reported the transfer of ₹2.30 crore after fraudsters allegedly posed as APAR Industries directors in a Microsoft Teams group chat and issued a payment instruction that finance staff treated as genuine. The Free Press Journal, citing the FIR filed with Mumbai’s South Cyber Police Station, reports that the transfer was initiated on July 31 and flagged only during a later review of the day’s transactions. The incident is a costly example of a control failure that Windows and Microsoft 365 administrators cannot solve solely with stronger Teams settings: an attacker did not need to deploy malware, take over a workstation, or bypass an RTGS banking control. According to the police complaint described by the Free Press Journal, the attackers persuaded authorized employees to perform the payment themselves.
APAR Industries’ own corporate disclosures identify Kushal N. Desai as chairman and managing director and Chaitanya N. Desai as managing director, matching the executives allegedly impersonated in the chat. The company’s March 2026 governance filing also lists Vinayak K. Lele as senior vice president of finance and a member of its risk-management committee, corroborating the organizational roles described in the complaint. That is important context: this was not a random “CEO fraud” message sent to a junior employee. The alleged attackers selected the people and relationships needed to make a high-value payment look procedurally normal.
No public statement from APAR Industries, Mumbai Police, Bandhan Bank, or Microsoft was located independently confirming the ₹2.30 crore loss, the recipient account, or whether any funds were frozen or recovered. Those details therefore remain allegations in the FIR as reported by the Free Press Journal, rather than established findings from the investigation.

Employees scrutinize an urgent RTGS payment request flagged for verification before paying.The Teams chat reportedly supplied the missing social proof​

The reported sequence is unusually revealing. The Free Press Journal says Lele was added at about 2:55 p.m. to a Teams group called “Work Group,” which appeared to contain accounts using the names and Teams identities of both Desai brothers. Before Lele joined, the attackers had apparently seeded the chat with a discussion about a business contract.
That preloaded conversation is the key tactic. A direct message ordering a ₹2.30 crore transfer should prompt suspicion; an executive request appearing at the end of an ongoing conversation between two real company leaders can instead look like an operational decision that the finance department merely has to execute. The fraudulent group chat became a substitute for a verbal approval trail.
The apparent Kushal Desai account then asked for the company’s bank balance, according to the report, and directed Lele to transfer ₹23 million to an entity called MB Rubber in West Bengal. The beneficiary banking details, reportedly at Bandhan Bank, were posted in the chat. Lele then instructed senior manager Parameswaran Mahadev Ayyar to process the RTGS payment, and the transfer confirmation was allegedly returned to the Teams group at the attacker’s request.
This is business email compromise without the email. The attack works because collaboration platforms inherit the authority workers ordinarily assign to the people and work threads inside them. Once the message reaches the payment approver with a convincing enough identity, a bank’s authentication mechanisms validate that an authorized customer ordered a payment—not that the business purpose behind it was legitimate.
Microsoft’s own documentation recognizes impersonation and phishing as risks in external Teams chats. Its guidance tells users to inspect the sender’s identity, including email address, and to accept external conversations only when the sender is trustworthy. Microsoft also tells users receiving an unexpected or urgent request involving money to verify it through a separate, trusted channel. The alleged APAR case shows why these instructions need to be treated as payment-control requirements rather than generic awareness advice.

The fraud was caught by a review, not a Teams warning​

According to the FIR account, the transfer was discovered later on July 31 when Arpan Shah reviewed the day’s transactions and questioned the unusually large payment. The payee was not a regular business associate, which led to the decisive question: had Lele spoken directly with Kushal Desai?
The reported answer was no. When the officials contacted Kushal Desai outside Teams, he denied creating the group or authorizing the transfer. That out-of-band check exposed the deception, but only after the RTGS instruction had been sent.
The practical lesson is sharper than “verify suspicious messages.” A finance team must have a mandatory verification path for every new beneficiary, material payment, or change to payment instructions, even when the request is shown in a familiar Teams thread and appears to come from an executive. The transaction should not be released until the approver contacts the executive using a known phone number, an existing verified chat, or another independent channel.
An approval path built around the same chat the attacker controls is not independent verification. Asking the alleged executive to confirm the payment in the Teams group, requesting a reply from the same account, or accepting a Teams-supplied callback number simply gives the attacker another opportunity to ratify their own instruction.
For many organizations, the appropriate rule is a two-person, two-channel control: one employee validates the commercial basis for a new payment, while another independently verifies the executive request using pre-established contact information. The second check must happen before the bank release, not as part of reconciliation afterward.

Teams identity is not the same thing as executive identity​

The most consequential unanswered technical detail is how the alleged impostors came to appear as the company’s directors. The reporting says they used what looked like genuine Teams IDs, but it does not establish whether the attackers compromised corporate Microsoft 365 accounts, created lookalike unmanaged Microsoft accounts, exploited Teams external access, or used some other identity configuration.
Those scenarios are very different for incident responders.
If the accounts were actually compromised, APAR would need to treat the episode as a broader Microsoft Entra ID and Microsoft 365 identity incident: revoke sessions, reset credentials, inspect multifactor-authentication changes, search sign-in and audit logs, review OAuth consents, examine mailbox and Teams activity, and assess whether the attackers accessed other company data.
If the attackers instead used external accounts or lookalike identities, the core failure may lie in Teams’ cross-tenant or consumer-account communication policies and in weak user recognition of external identity labels. Microsoft Teams supports chats with users outside an organization when external access is enabled, and external users can be permitted or blocked at the tenant level. A name and familiar display image are not evidence that the account belongs to the named executive.
Microsoft’s 2026 threat research has separately documented attackers using external Teams communications to impersonate IT or help-desk workers. Those campaigns often aim to gain remote access through Quick Assist or comparable tools, then deepen the compromise with legitimate administrative utilities. The APAR incident, as alleged, took a shorter route: it converted trust in Teams directly into an authorized payment.
That distinction changes the response priority. Endpoint telemetry and EDR may find nothing when the victim’s employee enters a legitimate bank transfer. The useful evidence is likely to sit in Teams message records, Entra sign-in logs, external-access configuration, Conditional Access events, recipient-account tracing, bank communications, and the approval records surrounding the transfer.

The regulator had warned listed companies weeks earlier​

The reported July 31 transfer came two weeks after the Securities and Exchange Board of India issued a July 17 warning to regulated entities and listed companies about “Boss Scam” fraud. SEBI said it had been alerted by the Indian Cyber Crime Coordination Centre to schemes in which criminals impersonate CEOs, managing directors, senior executives, or trusted colleagues using email, WhatsApp, Microsoft Teams, and other platforms to direct fund transfers.
SEBI’s warning was explicit that organizations should strengthen internal controls and independently verify such requests. The regulator did not describe this as a theoretical phishing risk; it identified a payment-fraud method already reaching listed companies through the same communication tools used for routine work.
APAR Industries is listed, and its governance reports show a formal risk-management structure. The public record does not establish what controls APAR had in place at the time of the alleged fraud or whether any rule was bypassed. But the reported facts point to a gap that many enterprises share: approving an RTGS transfer may require the right internal banking authority while still lacking a reliable test that the underlying executive instruction is authentic.
That gap cannot be closed by pushing a security-awareness email after the fact. It requires a payment policy that treats a Teams message—whether it appears internal, external, or comes from an executive account—as insufficient authorization for a new or exceptional beneficiary.

What Microsoft 365 administrators should change now​

Teams administrators should start by inventorying every route through which people outside the tenant can reach finance, treasury, procurement, executive-assistant, and senior-management staff. External access may be operationally necessary, but “needed by some employees” is not a reason to leave it broadly open for every user handling payments.
The immediate measures are straightforward:
  • Restrict Teams external access to approved partner domains where the business can support an allowlist model, and disable unnecessary communication with unmanaged Microsoft accounts.
  • Make external identity status visible in user training and ensure finance staff know where to inspect the actual account address and organization rather than relying on a display name, avatar, or conversation history.
  • Define monetary thresholds and beneficiary-change conditions that require direct, recorded confirmation through a separate trusted route.
  • Block payment approval based only on chat messages, including messages from accounts belonging to executives, until the required out-of-band confirmation is attached to the transaction record.
  • Ensure Teams and Entra audit logging is retained long enough to support a financial-fraud investigation, and test whether the security team can retrieve membership, message, sign-in, and external-access evidence quickly.
  • Give staff a clear escalation route for suspected payment impersonation, including immediate contact with the bank and India’s 1930 cybercrime helpline. India’s National Cyber Crime Portal specifically directs victims of cyber financial fraud to report promptly through 1930.
The case is still under investigation, and there is no public indication of whether the alleged recipient accounts were frozen in time. But the operational conclusion is already clear: Teams must be treated as an untrusted transport for payment instructions, even when a chat looks internal and appears to include the company’s most senior executives.

References​

  1. Primary source: Free Press Journal
    Published: 2026-08-06T15:05:46+00:00
  2. Related coverage: support.microsoft.com
  3. Related coverage: support.microsoft.com
  4. Related coverage: learn.microsoft.com
  5. Related coverage: learn.microsoft.com
  6. Related coverage: microsoft.com
  7. Related coverage: cdn-dynmedia-1.microsoft.com
  8. Related coverage: cdn-dynmedia-1.microsoft.com
  9. Related coverage: download.microsoft.com
  10. Related coverage: news.microsoft.com
  11. Related coverage: techcommunity.microsoft.com
  12. Related coverage: microsoft.com
  13. Related coverage: expertinsights.com
  14. Related coverage: blogs.microsoft.com
  15. Related coverage: cyberproof.com
  16. Related coverage: techrepublic.com
  17. Related coverage: bleepingcomputer.com
  18. Related coverage: taxguru.in
  19. Related coverage: freepressjournal.in
  20. Related coverage: csoonline.com
  21. Related coverage: timesofindia.indiatimes.com
  22. Related coverage: cyberdefensemagazine.com
  23. Related coverage: sebi.gov.in