1 hr ago
CEO Impersonation Scams Exploit WhatsApp, Email and Teams
Scammers sometimes pretend to be a company boss in messages or calls.
They may use email, WhatsApp, Teams, or fake video and voice technology.
The fake boss can tell an employee to send money quickly.
The money is sent to an account controlled by the scammer.
Some scammers send ZIP files that contain harmful computer programs.
Opening one can let them take over a WhatsApp Web session.
They may then message other employees while pretending to be the boss.
Workers should check unusual requests by calling the real executive and should not open suspicious files.
Fraudsters impersonate CEOs and senior officials to persuade employees to transfer money to scam-controlled accounts.
Attackers may use AI-generated voices, video calls, or fake social media groups to make impersonations appear genuine.
Malicious ZIP files containing executable files can install malware and hijack active WhatsApp Web sessions.
Compromised accounts may be used to pressure employees into making urgent payments or to alter contact lists.
Companies are advised to verify requests independently, avoid opening suspicious files, log out of unused WhatsApp Web sessions, and report incidents to 1930 or cybercrime.gov.in.
- Who
- Fraudsters impersonating CEOs, managing directors, and other senior officials target employees, especially finance officers.
- What
- The scammers use digital messages, deepfakes, and malicious files to trick companies into transferring money or to hijack WhatsApp Web accounts.
- Where
- The scams operate through digital platforms, including WhatsApp, email, Teams, social media groups, and Windows computers.
- When
- Why
- The attackers seek to make victims send money to accounts controlled by the scammers.
Key facts
- Primary fraud method
- Impersonating CEOs or other senior officials through digital communications
- Targeted employees
- Subordinates, counterparts, and finance officers
- Technical attack
- Malicious ZIP files may contain .exe and .dll files that install a Trojan dropper
- Account risk
- Attackers may hijack active WhatsApp Web session tokens
- Social engineering tactic
- Victims may be pressured to make urgent or confidential payments
- Recommended verification
- Independently call the purported executive before acting on a request
- Reporting channels
- 1930 and cybercrime.gov.in








