A new cyber scam is targeting CAs, business owners, and finance staff β here’s everything you must know to stay safe
Introduction: Imagine This Happening to Youβ¦
You work in the accounts department of a company. One morning, your boss β a senior executive β sends you a WhatsApp message. It says: “Transfer βΉ5 lakhs urgently to this account. Client deal is closing today. Do it immediately.”
You trust your boss. The message came from his WhatsApp number. You transfer the money.
But here’s the terrifying truth β your boss never sent that message. A criminal had taken over his WhatsApp account and was pretending to be him. By the time anyone realises what happened, the money is gone β transferred to a fake “mule” bank account controlled by fraudsters.
This is not a movie plot. This is happening right now, across India β in Delhi, Gujarat, Maharashtra, and Rajasthan.
The Government of India’s cyber crime unit has raised a serious alarm. Thousands of Indians are already at risk. This article explains exactly what this scam is, how it works, who is being targeted, and most importantly β how you can protect yourself and your organisation.
π Section 1: Who Is Warning Us and Why Should We Take It Seriously?
The warning has come from the Indian Cyber Crime Coordination Centre (I4C), which works under the Ministry of Home Affairs (MHA) β the same ministry that oversees the police and national security.
I4C monitors cyber crimes reported on the National Cyber Crime Reporting Portal (NCRP) β India’s official platform where people report online fraud. They noticed a sudden and sharp rise in complaints from multiple states, all following the exact same pattern of attack.
This is not a one-off incident. It is an organised, cross-border criminal campaign targeting corporate India.
π‘ Think of I4C like a national cyber police station that watches for threats before they spread β and then alerts people to protect themselves.
π Section 2: What Is This Scam Called and What Makes It So Dangerous?
This scam goes by two names:
- “Boss Scam” β because criminals pretend to be your boss or CEO
- “CEO Impersonation Fraud” β same idea, targeting top company executives
What makes it especially dangerous is that it uses a self-propagating malware β meaning, once it infects one person’s computer, it automatically spreads itself to everyone in that person’s WhatsApp contacts and groups. It spreads like a virus β silently, quickly, and automatically.
π‘ Think of it like a disease. Once one person in an office catches it, it spreads to everyone they’ve been in contact with β without anyone even knowing.
π Section 3: How Does the Scam Actually Work? (Step-by-Step)
Let’s break this down simply, step by step:
π΄ STEP 1: You Receive a Suspicious File
You get a message on WhatsApp, SMS, or email with a compressed file (a .zip file β like a folder packed tightly) with names like:
Statement of Account.zip0714 Statement of Account.zipRBI.zipMCA.zip
The message looks very official. It either says it’s a routine bank account statement OR an urgent notice from the RBI (Reserve Bank of India) or MCA (Ministry of Corporate Affairs) β asking you to comply within a very short time.
Sometimes, emails are also sent pretending to be from the Income Tax Department.
π‘ This is like someone putting a fake “government stamp” on a letter to make you open it without questioning.
π΄ STEP 2: You Extract and Open the File on Your Computer
When you extract (open) the .zip file on your Windows computer or laptop, you find what looks like a document β but hidden inside is a malicious .exe file (an executable file β a programme that runs on your computer) and a .dll file (a support file that helps the programme run).
The moment you click and open it β a Trojan is installed on your computer.
π‘ A “Trojan” in cyber terms is like a spy that hides inside something that looks safe. Just like the story of the Trojan Horse β soldiers hidden inside a wooden gift.
π΄ STEP 3: The Criminal Takes Over Your WhatsApp
Once the Trojan is installed, it hijacks your active WhatsApp Web session β meaning, if you use WhatsApp on your browser or computer (WhatsApp Web), the criminal now has access to your entire WhatsApp account.
They can read your messages, send messages pretending to be you, and access all your contacts and groups.
π΄ STEP 4: The Malware Spreads to Everyone You Know
Your compromised WhatsApp account now automatically sends the same malicious .zip file to all your contacts and groups β often with a message like:
“Please forward this to your company finance manager for verification and open it on a computer.”
This way, the infection spreads from one person’s device to an entire corporate network.
π΄ STEP 5: The “Boss Scam” β Money Gets Stolen
In the final and most damaging stage, the criminals use the hijacked WhatsApp account of a senior executive (CEO, Director, CFO) to message finance and accounts employees with urgent instructions to transfer money to certain bank accounts.
These are “mule accounts” β fake or illegally obtained accounts used to receive and quickly move stolen money.
The employee, believing it’s their boss, transfers the funds. The money vanishes.
π Section 4: Who Is Being Targeted? β The High-Risk Group
Because this malware only activates on Windows computers and uses files that look like financial documents, it specifically targets professionals who handle money and compliance work.
| Category | Why They Are Targeted |
|---|---|
| Chartered Accountants (CAs) | Handle client accounts, financial data, and deal with RBI/MCA regularly |
| Company Directors | Senior decision-makers whose WhatsApp is trusted by employees |
| Chief Financial Officers (CFOs) | Control company funds and have authority over transfers |
| Finance & Accounts Staff | Execute fund transfers on instructions from seniors |
| Corporate Finance Teams | Handle day-to-day transactions and vendor payments |
π‘ In simple words β if your job involves money, accounts, or compliance β you are the prime target.
π Section 5: The Numbers β How Big Is This Problem?
Here is a clear picture of the scale of this threat, in numbers:
| Data Point | Number / Detail |
|---|---|
| States where cases reported | Delhi, Gujarat, Maharashtra, Rajasthan (and more) |
| Potential victims warned by I4C via SMS | Over 58,000 people in the last 30 days |
| Indians protected from this campaign so far | More than 10,000 |
| SMS Header used to send alerts | I4CMHA-G |
| I4C Advisory first issued on | 22nd June, 2026 |
| Helpline number for reporting | 1930 |
| Online reporting portal | www.cybercrime.gov.in |
π Section 6: What Is the Government Doing to Stop This?
The Government is not sitting idle. Here’s what I4C has already done:
β Action 1: Warning Victims Directly
I4C is identifying potential victims through complaint analysis and technical intelligence, and proactively sending them SMS alerts β so they can take action before they lose money or data.
β Action 2: Sharing Threat Information With Tech Companies
I4C has shared technical details of this malware with:
- CERT-In (India’s Computer Emergency Response Team β the government’s cyber security body)
- Microsoft Defender (built-in security in Windows)
- Quick Heal (Indian antivirus company)
- K7 Computing (Indian antivirus company)
- Net Protector (Indian antivirus company)
This means these security tools are being updated to detect and block these malicious files.
β Action 3: Blocking Criminal Servers Through Sahyog Portal
The criminals’ computers (called C2 Servers β Command and Control Servers β the computers that control the malware remotely) are being geo-blocked through the Sahyog Portal.
π‘ Think of this as the government blocking a criminal’s phone line so they can’t give orders to their network anymore.
β Action 4: Sending SMS Alerts to Citizens
I4C is actively sending alerts under the SMS header ‘I4CMHA-G’. If you get an SMS from this header β read it carefully and act on it immediately. It’s a genuine government warning.
π Section 7: YOUR RIGHTS AND WHAT THIS MEANS FOR YOU
This section is especially for you β the common person, the employee, the business owner, and the CA.
π‘οΈ You Have the Right to:
β
Be warned before you become a victim β and the government is doing this through SMS
β
Report cyber fraud without going to a police station β just call 1930 or visit www.cybercrime.gov.in
β
Get your computer scanned and cleaned if infected
β
Ask your company’s IT team to check your systems immediately
π What This Scam Means for Everyday Life:
- If you’re a CA or finance professional β a file that looks like a client statement could destroy your entire contact list’s security and lead to massive financial fraud
- If you’re a company employee β a WhatsApp message from your “boss” may not really be from your boss
- If you’re a business owner β your WhatsApp being hacked can make your clients and vendors victims too
- If you use WhatsApp Web β your session could be hijacked without you even knowing
π Section 8: What You MUST Do Right Now β Your Safety Checklist
β DO NOT:
β Open any .zip file received over WhatsApp, SMS, or email from unknown sources
β Extract or run any .exe file received from anyone β even someone you know
β Believe that RBI, MCA, or Income Tax Department sends files or software through WhatsApp
β Transfer money just because a WhatsApp message from your “boss” says to β always verify by calling them directly
β DO IMMEDIATELY:
β
Check your WhatsApp Linked Devices β Go to WhatsApp β Settings β Linked Devices β Log out of any session you don’t recognise
β
Call and verify any urgent money transfer request β even if it comes from a senior’s WhatsApp number
β
Update your antivirus software on your Windows computer right now
β
Alert your finance team β share this article with them
β
Watch for SMS from I4CMHA-G β if you receive one, act on the advice immediately
π IF YOUR ACCOUNT IS ALREADY COMPROMISED:
β
Step 1: Log out of all linked WhatsApp devices immediately (Settings β Linked Devices β Log out all)
β
Step 2: Alert all your contacts β tell them NOT to open any file they received from your number
β
Step 3: Get your computer scanned by an updated antivirus
β
Step 4: Report the incident on www.cybercrime.gov.in or call 1930
β
Step 5: Inform your company’s IT administrator immediately
π’ IF YOU ARE A SYSTEM ADMINISTRATOR (IT Manager of a Company):
β
Block the execution of unknown .exe and .dll files from user profile directories
β
Ensure all Windows computers in your organisation run up-to-date antivirus solutions
β
Enforce software restriction policies immediately
β
Conduct an emergency awareness session for your finance and accounts team
π Section 9: Simple Analogy β Understanding This Scam Like Never Before
Imagine you receive a sealed envelope that looks like it came from your bank β with the bank’s logo and everything. Inside is a key, and the letter says: “Use this key to check your locker urgently.”
You use the key. But the moment you do β the key makes a copy of itself, secretly enters every room in your building, and hands a copy of your locker access to a thief who is watching from outside.
That’s exactly what this malware does β on your computer and your WhatsApp.
The lesson? Don’t use any “key” (file) unless you are 100% sure who sent it and why.
Conclusion: Spread Awareness β You Could Save Someone’s Life Savings
This scam is not just a technical problem β it is a direct threat to your money, your business, and your reputation. Criminals are organised, well-funded, and operating from across international borders. But they rely on one thing β that you won’t know about this until it’s too late.
Now you know.
Share this article with your colleagues, your CA, your accountant, your company’s finance team, and your family members who use WhatsApp on a computer. You might just save someone from losing their life savings or their company’s funds.
Remember:
π Real government agencies like RBI, MCA, and Income Tax will NEVER send you software files or account statements through WhatsApp. If you receive one β delete it immediately.
π Helpline: 1930
π Report Online: www.cybercrime.gov.in
π± Watch for SMS from: I4CMHA-G
π Source
Press Release by: Indian Cyber Crime Coordination Centre (I4C), Ministry of Home Affairs, Government of India
Release ID: 2295889
Date of Release: 07 August 2026
Original Advisory issued by I4C on: 22nd June, 2026
Available at: www.cybercrime.gov.in
π Please share this article widely. Cyber safety is everyone’s responsibility.
Leave a Reply