Ministry Issues Warning on WhatsApp 'Boss Scam' Targeting Finance Professionals
Article Content
- •The 'Boss Scam' targets finance professionals by hijacking WhatsApp accounts.
- •Malware is distributed via compressed files disguised as legitimate documents.
- •I4C recommends immediate verification of urgent fund transfer requests.
The Indian Cyber Crime Coordination Centre (I4C) has issued a warning about the 'Boss Scam', where attackers hijack WhatsApp accounts of finance professionals using malware disguised as account statements. The malware, which activates on Windows systems, is spread through compressed files labeled as 'Statement of Account.zip', 'RBI.zip', or 'MCA.zip'. This scam has seen a significant rise in complaints across multiple states, including Delhi, Gujarat, Maharashtra, and Rajasthan. Cybercriminals exploit compromised accounts to send urgent fund transfer requests, often impersonating senior executives. The I4C has advised organizations to verify any urgent requests through direct communication and to avoid opening files from unknown sources. A standard operating procedure has been issued to enhance security awareness among finance teams. Investigations are ongoing in collaboration with law enforcement agencies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…