MHA warns of ‘Boss Scam’ targeting corporate finance teams


Daijiworld Media Network - New Delhi

New Delhi, Aug 8: The Union Ministry of Home Affairs (MHA) has issued a nationwide advisory warning corporate entities, Chartered Accountants, company directors, Chief Financial Officers (CFOs) and other finance professionals about a rapidly spreading cyber fraud known as the ‘Boss Scam’, in which attackers compromise WhatsApp accounts to carry out high-value financial fraud.

The advisory follows a sharp rise in complaints received through the National Cyber Crime Reporting Portal (NCRP), with cases reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan.

According to the Indian Cyber Crime Coordination Centre (I4C) under the MHA, cybercriminals are using malicious files disguised as “Statement of Account”, “RBI” or “MCA” documents to infect Windows computers and hijack victims’ active WhatsApp Web sessions.

The malware is circulated through WhatsApp, SMS and email, often accompanied by messages posing as routine account statements or urgent regulatory notices requiring immediate action.

Technical analysis by the National Cybercrime Threat Analytics Unit (NCTAU), the cyber intelligence arm of the I4C, found that the campaign is being operated by organised cross-border cybercrime networks using advanced malware capable of evading detection through the DLL sideloading technique. Investigations are underway in coordination with law enforcement and technical agencies.

The MHA said the malware specifically targets Windows devices. Once a victim extracts and opens the malicious ZIP archive, a Trojan is installed, allowing criminals to compromise the computer and take control of the user's active WhatsApp Web session.

In some cases, fraudsters have also impersonated the Income Tax Department through phishing emails.

After gaining access, attackers use the compromised WhatsApp account to automatically circulate the same malicious files to the victim’s contacts and groups. Recipients are often asked to forward the document to their company’s finance manager for verification, enabling the malware to spread further within corporate networks.

In the final stage, cybercriminals exploit a genuine WhatsApp account belonging to a senior executive or manipulate contact details to impersonate a company CEO.

They then send urgent instructions to finance and accounts personnel, directing them to transfer funds to mule bank accounts.

Given the nature of the attack, the MHA said finance departments face the highest risk. It urged organisations to sensitise employees, particularly those handling financial transactions, and independently verify any urgent fund transfer request or change in bank account details received through WhatsApp or email.

Such requests should be verified through a direct phone call or in-person confirmation before any transaction is made.

The I4C has also issued a standard operating procedure (SOP) advising individuals and organisations not to download, extract or open ZIP files or executable programs received from unknown or unverified sources.

It clarified that regulators such as the Reserve Bank of India (RBI) do not distribute software updates, security patches or account statements through WhatsApp attachments.

Users have been advised to regularly check WhatsApp’s ‘Linked Devices’ section and log out of inactive WhatsApp Web sessions. System administrators have also been advised to block the execution of unknown executable (.exe) and Dynamic Link Library (.dll) files from user profile directories and ensure that Windows systems are protected with updated anti-malware software.

If an account is suspected to have been compromised, users should immediately log out of all linked devices, alert their contacts not to open files received from the affected account and scan the computer using updated antivirus software.

The latest advisory builds on an earlier warning issued by the I4C on June 22, 2026, titled “Regulatory and Executive Impersonation for WhatsApp Account Takeover Using Malicious Windows Executables and High-Value Financial Fraud.”

To counter the threat, the I4C said it has begun proactively alerting identified victims and potential targets based on complaint analysis and technical intelligence.

Threat indicators have also been shared with CERT-In, Microsoft Defender and Indian cybersecurity firms, including Quick Heal, K7 Computing and Net Protector, to facilitate rapid detection and blocking of the malware.

According to the ministry, these coordinated efforts have already protected more than 10,000 users, while over 58,000 potential victims have been alerted during the past month through SMS messages sent under the header “I4CMHA-G”.

The MHA urged citizens to act promptly on such alerts and report suspected cyber fraud by calling the National Cyber Crime Helpline at 1930 or through the National Cyber Crime Reporting Portal.

 

 

 

  

Top Stories


Leave a Comment

Title: MHA warns of ‘Boss Scam’ targeting corporate finance teams



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.