Central body warns corporates of ‘Boss Scam’ targeting WhatsApp accounts, finance teams

Ziraat Times News Desk

New Delhi, August 7: The Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs has warned corporate executives, Chartered Accountants, Company Directors, Chief Financial Officers and finance professionals about a growing cyber fraud campaign involving WhatsApp account takeovers and impersonation of senior executives.

The fraud, commonly referred to as the “Boss Scam” or CEO impersonation fraud, involves malicious files circulated through WhatsApp, SMS and e-mail in the guise of account statements or urgent communications from regulatory authorities. According to I4C, the campaign is being used to compromise the WhatsApp accounts of senior professionals and subsequently induce corporate finance staff to transfer money to mule bank accounts.

I4C said it has observed a sharp increase in complaints on the National Cyber Crime Reporting Portal relating to the takeover of WhatsApp accounts through malicious files. Similar incidents have been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan.

The agency had earlier alerted citizens to the threat through an advisory issued on June 22, 2026, warning about regulatory and executive impersonation being used for WhatsApp account takeover and high-value financial fraud.

Malicious files disguised as account statements

According to I4C, victims typically receive a compressed .zip file through WhatsApp, SMS or e-mail with names such as “Statement of Account.zip”, sometimes carrying a date prefix, or files named “RBI.zip” and “MCA.zip”.

The accompanying message is designed to appear either as a routine account statement or an urgent communication from institutions such as the Reserve Bank of India or the Ministry of Corporate Affairs, often demanding immediate compliance. In some cases, e-mails impersonating the Income Tax Department are also used.

The compressed archive contains a malicious Windows executable file along with a Dynamic Link Library (.dll) file. When extracted and opened on a Windows computer, the malware installs a Trojan that can compromise the device and hijack an active WhatsApp Web session.

Once an account is compromised, the malware can automatically circulate the same malicious file to the victim’s WhatsApp contacts and groups. Recipients may be asked to forward the file to their company’s finance manager “for verification” and open it on a computer, allowing the malware to spread further through corporate networks.

Senior executives impersonated to order fund transfers

In the advanced stage of the operation, fraudsters exploit the compromised WhatsApp account of a senior executive to issue apparently genuine instructions to accounts and finance personnel.

I4C said attackers may also covertly save an attacker-controlled number under the name of a company’s CEO on a compromised device. Using the trusted identity of a senior executive, they then issue urgent instructions for transferring funds to mule bank accounts.

Technical analysis by I4C’s National Cybercrime Threat Analytics Unit indicates that the campaign is being operated by organised networks working across national borders. The malware uses sophisticated propagation and detection-evasion techniques, including DLL sideloading, according to the agency.

Over 58,000 potential victims alerted

I4C said it has proactively identified and alerted victims and potential victims based on complaint analysis and technical intelligence.

More than 58,000 potential victims have been intimated over the past 30 days through SMS messages sent using the header “I4CMHA-G”, the agency said.

I4C has also shared threat signals and technical indicators associated with the malware with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender and Indian cybersecurity companies including Quick Heal, K7 Computing and Net Protector.

Through coordinated intervention and blocking of malware command-and-control servers through the Sahyog Portal, more than 10,000 Indians have so far been protected from the campaign, I4C said.

Direct verification advised for fund-transfer requests

Given the malware’s Windows-specific nature and its focus on account statements and regulatory compliance, I4C said the campaign poses a particular risk to professional and corporate finance networks.

It has advised companies to sensitise employees, particularly finance and accounts personnel, and to independently verify any urgent fund-transfer or account-change request received through WhatsApp or e-mail.

Such verification should preferably be carried out through a direct voice call or in-person confirmation, rather than by replying to the same WhatsApp conversation or e-mail.

I4C has advised citizens and organisations not to download, extract or open .zip files or executable files received from unknown or unverified sources. It also cautioned that regulatory institutions such as the RBI do not distribute software updates, security fixes or account statements through WhatsApp attachments.

Users have been advised to regularly check WhatsApp Settings > Linked Devices and log out of sessions that are no longer in use.

System administrators have also been asked to restrict the execution of unknown .exe and .dll files from user-profile directories and ensure that Windows systems are protected with updated anti-malware software.

If a WhatsApp account is compromised, I4C has advised users to immediately log out of all linked devices, warn their contacts not to open files received from the account and scan the affected computer with updated antivirus software.

Cyber fraud and suspicious communications can be reported through the National Cyber Crime Helpline 1930 or the National Cyber Crime Reporting Portal. Citizens receiving alerts from the “I4CMHA-G” SMS header have been advised to read and act promptly on the instructions contained in those messages.

13 COMMENTS

  1. … [Trackback]

    […] Read More Infos here: ziraattimes.com/2026/08/central-body-warns-corporates-of-boss-scam-targeting-whatsapp-accounts-finance-teams/ […]

  2. It’s concerning to see how the ‘Boss Scam’ is specifically targeting WhatsApp accounts within finance teams. Corporates really need to stay vigilant about these tactics to protect their sensitive information. useful tool

  3. It’s alarming to hear about the rise of the ‘Boss Scam’ that specifically targets finance teams via WhatsApp. This highlights the need for better training on recognizing such scams in corporate environments. Awareness is key to safeguarding against these threats. interesting find

  4. It’s alarming how the ‘Boss Scam’ exploits WhatsApp accounts to manipulate finance teams. Companies should prioritize educating their staff about these types of scams and implement stricter protocols for financial communications. worth a look

  5. It’s alarming to learn how the ‘Boss Scam’ exploits WhatsApp, especially targeting finance teams. Companies must enhance their security protocols and train employees to recognize such threats to safeguard their financial data effectively. interesting find

LEAVE A REPLY

Please enter your comment!
Please enter your name here