3 weeks ago
Boss Scam: How Hackers Hijack WhatsApp CEO Accounts for Fraud
Some bad people are pretending to be company bosses to steal money.
They send a message that looks like it comes from a big government office, with a file attached.
If someone opens the file, a secret program sneaks into their computer.
The program can take over the boss's real WhatsApp account.
Then the bad people send urgent messages from the boss's account asking for money.
Workers may think the message is real and send the money, but it goes to the scammers.
A special group in India called I4C works to stop these scams.
They have protected more than 10,000 people and warned over 58,000 others.
To stay safe, always check with a real person by phone or face to face before sending money.
Never open strange computer files, and keep your computer and apps updated.
The 'Boss Scam' is a cyber fraud where criminals impersonate a company's CEO or senior executive to pressure employees into unauthorized financial transfers.
In the latest variant, scammers first compromise an executive's computer and hijack their active WhatsApp Web session, removing the warning sign of an unrecognized number.
Attackers send malicious ZIP files named 'RBI.zip', 'MCA.zip' or 'Statement of Account.zip' containing Windows .exe and .dll files that use DLL sideloading to evade detection.
I4C says coordinated action has protected more than 10,000 Indians and alerted over 58,000 potential victims in the last 30 days.
Experts advise verifying urgent payment requests by voice call or in person, avoiding unknown ZIP files, and checking WhatsApp linked devices regularly.
- Who
- Scammers impersonating CEOs and senior executives, targeting corporate and finance employees in India; the Indian Cyber Crime Coordination Centre (I4C) issued the warning.
- What
- A cyber fraud campaign, the 'Boss Scam', in which malware hijacks a senior executive's WhatsApp Web session to send urgent fake payment requests.
- Where
- India, across multiple states.
- When
- Latest cases reported across multiple states; I4C first warned about this tactic on June 22, 2026, and alerted over 58,000 potential victims in the last 30 days.
- Why
- Criminals exploit employee trust in senior management, using authority and urgency to direct unauthorized payments into accounts they control.
Key facts
- Scam name
- Boss Scam / CEO impersonation fraud
- Attack vector
- Hijacked WhatsApp Web session of a real senior executive
- Malicious file names
- Statement of Account.zip, RBI.zip, MCA.zip
- Malware technique
- DLL sideloading with Windows .exe and .dll files
- Indians protected
- More than 10,000
- Victims alerted (30 days)
- Over 58,000 via SMS header 'I4CMHA-G'
- First I4C advisory
- June 22, 2026
- Reporting channel
- National Cyber Crime Helpline 1930 or National Cyber Crime Reporting Portal










