PIB Daily Digest

Search PIB intelligence

Jump to dashboards and focused views.

Back to dashboard
Ministry of Home Affairs

I4C cautions corporates and finance professionals against ‘Boss Scam’: WhatsApp account takeover through malicious ‘Statement of Account’, ‘MCA’ and ‘RBI’ files aimed at high-value financial fraud

MainsGS2GS3Science & TechnologyGovernanceEconomySecurity
Source-grounded summary

The Indian Cyber Crime Coordination Centre (I4C) of the Ministry of Home Affairs reports a sharp rise in WhatsApp‑account takeover scams targeting chartered accountants, company directors, CFOs and finance teams. Fraudsters circulate zip files named “Statement of Account.zip”, “RBI.zip” or “MCA.zip” via WhatsApp, SMS or e‑mail; the archives contain a malicious Windows executable and DLL that install a Trojan, hijack the victim’s WhatsApp Web session and propagate the file to contacts. The compromised senior‑executive accounts are then used to instruct finance staff to transfer funds to mule accounts – a scheme dubbed the “Boss Scam”. I4C has intimated over 58,000 potential victims, protected more than 10,000 Indians through geo‑blocking, and shared threat indicators with CERT‑In, Microsoft and Indian anti‑virus firms. It advises organisations to verify urgent fund‑transfer requests and to enforce strict software‑restriction policies.

Notes are generated only from linked official PIB content. Always verify the source.