The Boss Scam: How fraudsters hijack CEOs' WhatsApp to steal company funds

The Boss Scam: How fraudsters hijack CEOs' WhatsApp to steal company funds

Under the 'Boss Scam', criminals use malware to hijack WhatsApp or email to impersonate senior executives and trick finance employees into urgently transferring company funds.The ‘Boss Scam’ uses fake messages from senior executives to trick employees into transferring company funds. (Photo: Representational image)'Boss scam', a new cyber fraud, is putting corporate executives, chartered accountants, chief financial officers and other senior management on alert across several states. Fraudsters impersonate senior company officials and trick employees into transferring large sums of money from corporate accounts. With several firms reportedly losing lakhs, authorities have warned companies and employees to remain super vigilant.Officials call it a 'Boss Scam' or CEO impersonation fraud, which can begin with something that appears routine, such as an account statement or regulatory document. In some cases, criminals send malicious files that infect a computer and take control of an active WhatsApp Web session.The compromised account can then be used to target trusted contacts, including employees in a company’s finance and accounts teams. Creating a sense of urgency, they persuade employees to transfer money to bank accounts controlled by criminals.The Indian Cyber Crime Coordination Centre (I4C) has issued a detailed advisory urging greater vigilance, while the Securities and Exchange Board of India (Sebi) has also warned of a rise in such incidents. HOW THE SCAM BEGINSThe fraud often starts with a message that appears legitimate.An employee may receive a file presented as a company account statement or regulatory communication. Some files are named "Statement of Account.zip", "0714 Statement of Account.zip", "RBI.zip" or "MCA.zip", according to officials. References to a bank, regulator or government department are designed to make the recipient believe that the communication is important and requires immediate attention.According to officials, these ZIP files contain malicious files and malware. When the victim extracts and opens the compressed file on a computer or laptop, the malware gets activated.The attack can then move beyond the infected device, taking total control of the device.The malware has capabilities that allow it to spread and evade detection. The fraudsters employ a technique called DLL Sideloading, in which malicious code is loaded through a legitimate application, helping it run while attempting to evade security checks.HOW WHATSAPP WEB BECOMES A TARGETOne of the most particular aspects of the scam is the malware’s ability to take control of an active WhatsApp Web session -- a WhatsApp window opened on browsers in laptops and desktops.Once attackers gain access, they can use the victim’s account to contact existing contacts and groups and send the same malicious file to others.The message accompanying the file may ask the recipient to share it with the company’s Finance Manager for verification and open it on a computer.Because the file comes from an account the recipient already knows, the communication can appear far more convincing than a message from an unknown number.This can create a chain of infection, with one compromised account helping criminals reach more employees and potentially gain access to other parts of an organisation, according to officials.Sebi has also highlighted this method, warning that malware-laden files can compromise devices or take over WhatsApp Web sessions, giving criminals access to internal communications.CRIMINALS THEN IMPERSONATE THE ‘BOSS’Once they gain access to an executive’s WhatsApp account, cybercriminals can impersonate a CEO or another senior company official and approach employees involved in financial operations. In some cases, attackers may also save a number under the name “CEO” on a target’s phone to make the communication appear genuine.The target is often an employee in the accounts or finance team. The employee may receive an urgent instruction to transfer money to a particular bank account, with the request presented as an immediate business requirement.Believing the instruction has come from a senior official, the employee may make the payment without independently checking it.This is why the fraud is called a ‘Boss Scam’.According to authorities, the scam is not limited to WhatsApp. Fraudsters are targeting finance executives and other employees through email, WhatsApp, Microsoft Teams and social media while posing as CEOs or other senior officials. The basic tactic remains the same to make a fraudulent request appear to be a genuine instruction from top management and pressure the recipient to act quickly.According to the Centre's Cyber Crime Centre, such cases have been reported from Delhi, Gujarat, Maharashtra and Rajasthan, among other states. It also said complaints of this nature on the National Cyber Crime Reporting Portal (NCRP) have been rising rapidly.ORGANISED NETWORKS OPERATINGTechnical analysis by the National Cybercrime Threat Analytics Unit (NCTAU) indicates that organised networks are behind the campaign. Some of these networks may also be operating across national borders.The cases are being investigated in coordination with relevant law enforcement and technical agencies, according to officials.WHY THE SCAM IS DIFFICULT TO DETECTThe most dangerous aspect of the ‘Boss Scam’ may not be the malware itself, but the trust it exploits. Cybercriminals do not always approach victims from unknown numbers. In some cases, they can send messages from a WhatsApp account the employee already knows and trusts. They can also use email, Microsoft Teams and social media to make their requests appear to be part of normal workplace communication.The combination of a familiar identity, an urgent request and a financial transaction can make the fraud particularly convincing.For companies, this makes internal cybersecurity awareness especially important.Authorities have advised entities under its supervision to strengthen internal controls and verification procedures before processing financial transactions.The regulator has specifically directed regulated entities to ensure that officials do not transfer funds solely on the basis of instructions received through social media platforms or messaging applications.- EndsPublished On: Aug 18, 2026 14:39 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.