What is the 'Boss Scam'? The WhatsApp Fraud That Can Empty Your Company's Bank Account

It starts with a message that looks completely ordinary. A ZIP file lands on WhatsApp, email or SMS. The filename appears harmless: "Statement of Account.zip." Sometimes it claims to be from the RBI. Sometimes from the Ministry of Corporate Affairs. Sometimes even from the Income Tax Department.
One click is all it takes.
According to the Indian Cyber Crime Coordination Centre (I4C), the malicious file installs malware that hijacks your WhatsApp account, impersonates senior executives and tricks finance teams into transferring money to fraudsters. Cases with the same modus operandi have now surfaced in Delhi, Gujarat, Maharashtra, Rajasthan and several other states.
What is the 'Boss Scam'?
The 'Boss Scam' is a sophisticated cyber fraud in which criminals first compromise the WhatsApp account of a senior executive, business owner or finance professional. Once inside, they use that trusted account to send urgent payment instructions to employees, asking them to transfer money into bank accounts controlled by the fraudsters. Because the messages appear to come from the boss's genuine WhatsApp account, employees often comply without questioning them.
The Age of Anger
31 Jul 2026 - Vol 05 | Issue 31
A raging generation makes the government relent. What's next?
How does the scam begin?
It begins with a fake ZIP file disguised as an account statement or an urgent regulatory communication. Victims receive attachments with names such as "Statement of Account.zip," "RBI.zip" or "MCA.zip", accompanied by messages designed to create urgency and pressure recipients into opening the file immediately. The real damage begins only after the ZIP file is extracted and opened on a Windows computer.
What happens after you open the file?
According to I4C, the archive contains a malicious Windows executable along with a supporting DLL file. Once opened, the malware silently installs itself and hijacks the victim's active WhatsApp Web session. The compromised account then begins automatically forwarding the same infected file to colleagues, clients and WhatsApp groups, often asking recipients to send it to their company's finance manager for verification. Every infected user effectively becomes the next link in the chain.
Why is it called the 'Boss Scam'?
Because the attackers weaponise trust. After taking control of a senior executive's WhatsApp account, fraudsters begin sending urgent instructions to finance and accounts teams asking them to make immediate fund transfers. In some cases, they even save an attacker-controlled number under the CEO's name to make the request appear genuine. Employees believe they are following legitimate instructions. In reality, they are sending company money to mule accounts operated by cybercriminals.
Who is most at risk?
I4C says the campaign poses the greatest risk to Chartered Accountants, Company Directors, Chief Financial Officers, finance professionals and business owners. Since the malware activates only on Windows computers and disguises itself as financial or regulatory documents, organisations handling sensitive financial transactions are especially vulnerable.
Who is behind these attacks?
Technical analysis by I4C's National Cybercrime Threat Analytics Unit (NCTAU) suggests the campaign is being operated by organised cybercrime networks working across national borders. Officials say the attackers are using advanced malware capable of evading detection through sophisticated techniques such as DLL sideloading, making it significantly more dangerous than conventional phishing attacks.
How widespread is the threat?
The government says complaints involving this exact modus operandi have risen sharply on the National Cyber Crime Reporting Portal. More than 58,000 potential victims have already been alerted through SMS messages sent under the header I4CMHA-G. Threat indicators have also been shared with CERT-In, Microsoft Defender and leading Indian cybersecurity companies, including Quick Heal, K7 Computing and Net Protector. According to I4C, these coordinated efforts have already protected more than 10,000 Indians from the campaign.
How can you protect yourself?
I4C advises people never to download or open ZIP files received from unknown or unverified sources. Regulators such as the Reserve Bank of India do not send software updates, compliance notices or account statements through WhatsApp attachments. Users should regularly check the Linked Devices section in WhatsApp and immediately log out of any unfamiliar sessions. Companies should also ensure that every urgent payment request received over WhatsApp or email is independently verified through a phone call or face-to-face confirmation before any money is transferred.
What should you do if your account is compromised?
Speed is critical. Immediately log out of all linked WhatsApp Web sessions, alert your contacts not to open any recent files received from your account and run a complete antivirus scan on your computer. The incident should then be reported to the National Cyber Crime Helpline 1930 or through the National Cyber Crime Reporting Portal. Because in the 'Boss Scam', the most dangerous WhatsApp message isn't the one you receive. It's the one your own account starts sending after you've already been hacked.
(With inputs from ANI)
