1 week ago

Hackers Exploit WhatsApp Web in Sophisticated CEO Fraud Attacks

Hackers Exploit WhatsApp Web in Sophisticated CEO Fraud Attacks
Cyber frauds reinvent whale phishing attacks, make it more invasive & deadly · indianexpress.com

Criminals are breaking into computers that have WhatsApp Web open.

They read old messages and learn how company leaders usually communicate.

Then they change saved contact details and pretend to be the company’s CEO.

Because the fake message appears in an old conversation, it can look real.

In one case, an accountant sent Rs 70 lakh before discovering the fraud.

Another company reportedly lost Rs 2.2 crore.

Police say workers should verify large payment requests by calling a trusted number.

Companies should also use extra login protection and require two people to approve large payments.

Key facts

Fraud method
Hijacking an active WhatsApp Web session after a victim opens a malicious file or link.
Impersonation technique
Fraudsters block or rename the genuine CEO contact and replace it with a fraudulent number using the CEO’s name and photograph.
Ravet loss
An accountant transferred Rs 70 lakh to a specified bank account before becoming suspicious.
Second requested transfer
The same fraudster later requested another Rs 30 lakh, prompting the accountant to contact the CEO.
Automobile dealer loss
An automobile dealer company was reportedly defrauded of Rs 2.2 crore.
Reported case volume
Pune City and Pimpri Chinchwad police have registered more than two dozen whale-phishing cases since 2022.
Recommended safeguard
Verify large or changed payment instructions through a known phone number and use dual approval for high-value transactions.

Quotes

Rohidas Pawar, Deputy Commissioner of Police (Crime) for Pimpri Chinchwad

Deputy Commissioner of Police

“We have seen instances where fraudsters hack WhatsApp Web sessions and then alter the victim’s contact list. They save the genuine number of the CEO under a different name and block it and then replace it with a fraudulent number carrying the CEO’s name and display picture, as a result, messages from the fraudsters appear to come from a trusted contact already saved in the phone.”
indianexpress.com
“The technique exploits trust built over months or years of legitimate communication. By studying previous exchanges, fraudsters can replicate language, tone and working patterns of senior executives. The fraudulent requests are often marked as urgent or confidential and are accompanied by instructions not to discuss them with others.”
indianexpress.com

Sources

Related news