Ministry Issues Warning on WhatsApp 'Boss Scam' Targeting Finance Professionals

Ministry Issues Warning on WhatsApp 'Boss Scam' Targeting Finance Professionals

First seen 7 Aug 2026, 18:12 UTC ThehindubusinesslineNewindianexpressTribuneindiawww.pib.gov.in 91% similarity 71.0

Article Content

Browse articles
ThreatCluster

The Indian Cyber Crime Coordination Centre (I4C) has issued a warning about the 'Boss Scam', where attackers hijack WhatsApp accounts of finance professionals using malware disguised as account statements. The malware, which activates on Windows systems, is spread through compressed files labeled as 'Statement of Account.zip', 'RBI.zip', or 'MCA.zip'. This scam has seen a significant rise in complaints across multiple states, including Delhi, Gujarat, Maharashtra, and Rajasthan. Cybercriminals exploit compromised accounts to send urgent fund transfer requests, often impersonating senior executives. The I4C has advised organizations to verify any urgent requests through direct communication and to avoid opening files from unknown sources. A standard operating procedure has been issued to enhance security awareness among finance teams. Investigations are ongoing in collaboration with law enforcement agencies.

Key Points: • The 'Boss Scam' targets finance professionals by hijacking WhatsApp accounts. • Malware is distributed via compressed files disguised as legitimate documents. • I4C recommends immediate verification of urgent fund transfer requests.

ThreatCluster AI How this analysis works

Timeline

2026-06-22
Initial advisory issued by I4C
I4C alerted the public about the emerging threat of the 'Boss Scam' targeting finance professionals.
Thehindubusinessline
2026-08-07
Nationwide warning issued
I4C warns about a surge in 'Boss Scam' cases, emphasizing the risk to finance personnel and companies.
Tribuneindia
2026-08-07
Malware analysis confirms attack method
Technical analysis reveals the use of DLL sideloading techniques to evade detection by the malware.
Newindianexpress

Community

Browse all →