India warns of escalating 'Boss Scam' tactics targeting corporate finance teams

India’s Home Ministry has issued a nationwide alert over a rapidly spreading cyber scam known as the ‘Boss Scam’, which exploits trust and urgency within corporate sectors to steal money through malware-infected messages and hijacked WhatsApp accounts.

India’s Home Ministry has issued a nationwide warning about a fast-growing cyber fraud scheme known as the “Boss Scam”, urging companies, chartered accountants, directors and finance professionals to treat urgent messages on WhatsApp and email with caution. The advisory follows a surge in complaints on the National Cyber Crime Reporting Portal, with reported cases in Delhi, Gujarat, Maharashtra and Rajasthan, according to the ministry and the Indian Cyber Crime Coordination Centre.

The scam typically begins with malicious files disguised as routine documents such as account statements or notices from regulators including the Reserve Bank of India or the Ministry of Corporate Affairs. Once a victim opens a ZIP file on a Windows machine, malware can be installed that hijacks an active WhatsApp Web session, allowing fraudsters to take over the account and spread the same file to colleagues and contacts, according to technical analysis cited by the I4C.

Cybersecurity reporting in India has linked the same method to cases in which attackers first impersonate a senior executive, then pressure staff in finance teams to send money to mule accounts. The New Indian Express reported in June that the I4C had already warned that the fraud relied on urgent claims of regulatory trouble to push victims into acting quickly, while The Indian Express described a recent case in which a malicious WhatsApp message was forwarded to an accountant, triggering a large transfer attempt.

The Home Ministry said finance departments are the highest-risk target because the scam depends on exploiting trust and urgency inside companies. It has advised staff to verify any request to change bank details or move funds through a direct phone call or in person, avoid opening ZIP or executable files from unknown senders, check WhatsApp’s linked devices list regularly and ensure Windows systems have updated anti-malware protection. The ministry said its alerting campaign has already protected more than 10,000 users and warned over 58,000 potential victims in the past month, while also urging people to report suspected fraud through the national helpline 1930.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.