I4C Warns of ‘Boss Scam’ – WhatsApp Account Takeover Targeting Finance Executives
The Indian Cyber Crime Coordination Centre (I4C) has warned of a large‑scale “Boss Scam” that hijacks WhatsApp accounts of senior finance officials through malicious zip files masquerading as RBI or MCA statements. Over 58,000 potential victims have been alerted and more than 10,000 users protected, highlighting the need for strict verification of fund‑transfer requests and robust cyber‑hygiene.
Overview The I4C has issued a fresh advisory on a large‑scale fraud that hijacks WhatsApp accounts of senior corporate officials. The scheme, popularly called the “ Boss Scam ”, spreads through malicious zip files that appear as RBI, MCA or account‑statement documents. Once a victim opens the file on a Windows PC, a Trojan installs, takes over the victim’s WhatsApp Web session and uses it to request fund transfers from finance teams. Key Developments (Bullet Points) Since 22 June 2026, I4C has recorded a sharp rise in complaints on the NCRP from Delhi, Gujarat, Maharashtra and Rajasthan. Malicious zip files are named “Statement of Account.zip”, “RBI.zip” or “MCA.zip” and contain a Windows .exe together with a .dll employing DLL Sideloading . Compromised accounts automatically forward the same malicious file to all contacts, urging them to send it to their “company finance manager”. In the final stage, attackers, posing as the CEO or senior executive, instruct finance staff to transfer money to mule accounts. Over 58,000 potential victims have been alerted via SMS header ‘I4CMHA‑G’ in the last 30 days, and more than 10,000 Indians have been protected through geo‑blocking of command‑and‑control servers via the Sahyog Portal . Important Facts The malware activates only on Windows computers, making Chartered Accountants, Company Directors, CFOs and finance teams the prime targets. I4C has shared technical indicators w
Quick Reference
Key Insight
I4C alerts on WhatsApp ‘Boss Scam’ targeting corporate finance officers – a cyber‑security threat for governance.
Key Facts
- I4C ने 22 June 2026 को ‘Boss Scam’ नामक WhatsApp Web टेकओवर स्कैम के बारे में एक सलाह जारी की।
- मालवेयर “Statement of Account.zip”, “RBI.zip” या “MCA.zip” नामक ज़िप फ़ाइलों के माध्यम से फैलता है।
- ज़िप में एक Windows .exe और एक दुर्भावनापूर्ण .dll शामिल है जो DLL sideloading का उपयोग करके स्थापित होता है।
- पिछले 30 दिनों में 58,000 से अधिक संभावित पीड़ितों को SMS के माध्यम से चेतावनी दी गई; 10,000+ उपयोगकर्ताओं की जियो‑ब्लॉकिंग द्वारा सुरक्षा की गई।
- यह स्कैम वरिष्ठ वित्त स्टाफ – CFOs, वित्त प्रबंधक, चार्टर्ड अकाउंटेंट – को Windows PC पर लक्षित करता है।
- I4C ने तेज़ पहचान के लिए CERT‑In, Microsoft Defender और भारतीय एंटी‑वायरस फर्मों के साथ संकेतक साझा किए।
- पीड़ितों को फंड‑ट्रांसफ़र अनुरोधों को वॉइस कॉल द्वारा सत्यापित करने और सभी WhatsApp जुड़े डिवाइसों से लॉग आउट करने की सलाह दी जाती है।
Background
Cyber‑security is now a key part of internal security and corporate governance in India. The I4C, under the Ministry of Home Affairs, coordinates cyber‑crime response across ministries, linking technology with policy. The scam threatens corporate liquidity and tests the effectiveness of existing cyber‑law frameworks.
UPSC Syllabus
- GS3 — Cyber security and communication networks in internal security
- GS3 — Indian Economy - Planning, mobilization of resources, growth, development and employment
- Prelims_GS — National Current Affairs
- GS2 — Government policies and interventions for development
Mains Angle
This issue can be discussed in GS 2 (Polity) on inter‑agency coordination and in GS 3 (Economy) on financial fraud impact. A possible Mains question may ask about strengthening cyber‑security governance to protect the corporate sector.