Boss Scam Targets CAs, CFOs and Companies: I4C Warns of WhatsApp Hijacking and High-Value Corporate Fraud
I4C has cautioned Chartered Accountants, Company Directors, CFOs and corporate finance teams against the rapidly spreading “Boss Scam”, in which malicious files disguised as account statements or RBI/MCA communications can compromise Windows computers and WhatsApp accounts before fraudsters impersonate senior executives and direct employees to transfer corporate funds. The threat has since developed beyond a cybersecurity advisory into a significant internal financial-control and corporate-governance issue. SEBI separately cautioned regulated entities and listed companies on 17 July 2026, while subsequent reported cases involving ₹7.8 crore, ₹10.4 crore and ₹6.8 crore demonstrate the financial consequences of treating WhatsApp or similar messaging platforms as sufficient authority for high-value payments.
- I4C sounds alarm over ‘Boss Scam’
- Chartered Accountants, CFOs and finance teams are prime targets
- How the Boss Scam works
- Stage 1: Fake regulatory or accounting communication
- Stage 2: Malicious ZIP file is opened on a Windows computer
- Stage 3: WhatsApp account or identity is compromised
- Stage 4: Finance employee receives an urgent payment instruction
- Stage 5: Malware spreads further
- Sophisticated malware uses DLL sideloading
- More than 58,000 potential victims alerted
- More than 10,000 Indians protected
- SEBI separately cautions listed companies and regulated entities
- ₹7.8 crore Delhi fraud shows danger of relying on apparent boss instructions
- ₹10.4 crore INOX case: 63 transactions allegedly made on WhatsApp instructions
- ₹6.8 crore Jaipur fraud shows conversation history itself may be manipulated
- Boss Scam is not confined to WhatsApp
- The common control failure: communication becomes payment authority
- Controls CFOs and finance teams should implement immediately
- Important audit and internal-audit implications
- Cybersecurity and financial controls must operate together
- Technical precautions recommended by I4C
- What should be done if the malicious file has already been opened?
- Report financial cyber fraud immediately on 1930
- Timeline: From emerging warning to multi-crore corporate fraud risk
- Conclusion: ‘Boss said so’ cannot be a financial control
I4C sounds alarm over ‘Boss Scam’
The Indian Cyber Crime Coordination Centre (I4C), Ministry of Home Affairs (MHA), has cautioned companies and finance professionals against an emerging cybercrime campaign popularly described as the “Boss Scam” or CEO impersonation fraud.
I4C first issued a specific advisory on 22 June 2026, titled “Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious Windows Executables and High value financial fraud”. It warned that cybercriminals were targeting CEOs and other senior executives by sending malicious archives through e-mail or WhatsApp under the guise of urgent regulatory compliance.
The threat escalated thereafter.
On 7 August 2026, MHA said I4C had observed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) relating to WhatsApp-account takeovers of professionals and businesspersons through malicious files disguised as account statements and regulatory communications.
Similar incidents had been reported from several States, including Delhi, Gujarat, Maharashtra and Rajasthan.
Chartered Accountants, CFOs and finance teams are prime targets
The campaign is particularly relevant to the financial and professional community because the malicious communications are deliberately designed to resemble documents that accountants and corporate executives routinely handle.
I4C specifically identified Chartered Accountants, Company Directors, Chief Financial Officers (CFOs) and corporate finance and accounts personnel as prime targets.
This targeting is reflected in the names given to the malicious files.
Victims may receive ZIP archives through WhatsApp, SMS or e-mail bearing names such as:
- “Statement of Account.zip”
- “0714 Statement of Account.zip”
- “RBI.zip”
- “MCA.zip”
The accompanying communication may appear to be a routine account statement or an urgent communication concerning regulatory compliance.
I4C has also stated that, in some cases, e-mails impersonating the Income Tax Department have been used. Taxpayers have separately been cautioned against fake Income Tax notices circulated through WhatsApp.
How the Boss Scam works
The fraud typically operates in stages.
Stage 1: Fake regulatory or accounting communication
The target receives a message apparently connected with a regulatory violation, security requirement, account statement or compliance matter.
The fraudster may impersonate an institution such as the Reserve Bank of India (RBI) or use other regulatory references to make the communication appear credible.
The message generally creates urgency by requiring action within a very short period.
Stage 2: Malicious ZIP file is opened on a Windows computer
According to I4C, the ZIP archive may contain a malicious Windows executable (.exe) accompanied by a Dynamic Link Library (.dll) file.
When extracted and opened on a Windows desktop or laptop, the malware installs a Trojan capable of compromising the computer and hijacking the victim’s active WhatsApp Web session.
Stage 3: WhatsApp account or identity is compromised
After gaining access, the fraudster can exploit the victim’s WhatsApp environment.
In one form of the attack, the genuine WhatsApp account of a senior executive is compromised.
In another, the attacker covertly saves an attacker-controlled number under the name of the CEO or other senior executive on the compromised device.
This creates the appearance that subsequent instructions are coming from the genuine boss.
Stage 4: Finance employee receives an urgent payment instruction
The attacker then communicates with an employee authorised to handle payments.
The employee may receive an apparently genuine instruction from the CEO, director, promoter or senior executive requiring an urgent transfer to a specified bank account.
The destination is generally a mule bank account used to receive and subsequently disperse the fraud proceeds.
Stage 5: Malware spreads further
The 7 August advisory revealed another serious feature: the malware can be self-propagating.
A compromised WhatsApp account can be misused to send the malicious file to the victim’s contacts and groups.
Recipients may be requested to forward the file to their “company finance manager for verification” and open it on a computer.
Thus, an infected businessperson, accountant or professional can unknowingly become the trusted source through which the attack reaches another organisation.
Sophisticated malware uses DLL sideloading
Technical analysis by I4C’s National Cybercrime Threat Analytics Unit (NCTAU) indicated that the campaign was being operated by organised networks acting across national borders.
According to MHA, the malware uses sophisticated propagation and detection-evasion capabilities, including the technique known as DLL sideloading.
Investigation is being pursued in coordination with the concerned law-enforcement and technical agencies.
More than 58,000 potential victims alerted
The scale of I4C’s preventive response illustrates the seriousness of the threat.
As of its 7 August announcement, I4C said it had intimated more than 58,000 potential victims during the preceding 30 days through the SMS header:
I4CMHA-G
Citizens receiving an alert under this header were advised to act promptly on the instructions contained in it.
More than 10,000 Indians protected
I4C also reported that more than 10,000 Indians had been protected from the campaign through coordinated interventions.
Malicious infrastructure was being blocked through the Government’s Sahyog Portal, including geo-blocking of command-and-control (C2) servers.
Threat signals and technical indicators associated with the malware were shared with:
CERT-In, Microsoft Defender, Quick Heal, K7 Computing and Net Protector
to facilitate rapid detection, blocking and removal of malicious files across platforms and security products.
SEBI separately cautions listed companies and regulated entities
The threat soon acquired an additional regulatory dimension.
On 17 July 2026, the Securities and Exchange Board of India issued Press Release No. 40/2026 — “Caution to Regulated entities and listed companies – Boss Scam.”
The official SEBI record confirms that the warning was specifically directed at regulated entities and listed companies.
This is significant because the Boss Scam is not merely an employee cybersecurity problem.
It can directly expose weaknesses in a company’s:
payment authorisation, maker-checker controls, beneficiary verification, escalation procedures, cybersecurity governance and protection of corporate funds.
The subsequent cases reported across India demonstrate how quickly such control weaknesses can translate into multi-crore financial losses.
₹7.8 crore Delhi fraud shows danger of relying on apparent boss instructions
One of the earliest major reported cases involved a company associated with former Rajya Sabha MP Naresh Gujral.
According to The Indian Express, a finance official received WhatsApp instructions appearing to come from his boss and, over several days, ₹7.8 crore was transferred through four transactions.
The bank itself became concerned about the unusually large transactions and contacted the company’s CFO. According to the report, the transfers were nevertheless allowed because the instructions were believed to have originated from Gujral. The fraud was subsequently discovered and approximately ₹4 crore was frozen following police intervention.
A subsequent investigation revealed a more sophisticated modus operandi.
Police sources told The Indian Express that a malicious message containing a ZIP file had initially been sent to a company director. The director forwarded it to the accountant for action. When the accountant opened the file, his WhatsApp environment was allegedly compromised.
The fraudsters then allegedly altered Gujral’s contact details and impersonated him while instructing the accountant to make RTGS transfers.
Investigators traced the movement of funds through multiple layers of mule accounts.
The case demonstrates a fundamental internal-control weakness:
A payment cannot be considered independently verified merely because an employee believes that the instruction originated from the company’s owner or senior management.
₹10.4 crore INOX case: 63 transactions allegedly made on WhatsApp instructions
An even larger reported Boss Scam emerged in Mumbai.
According to Mumbai Police, as reported by Hindustan Times, a fraudster allegedly impersonated a senior director of the INOX Group and contacted a deputy general manager in accounts through WhatsApp.
The communication began with the purported senior director saying that he was attending an important meeting and would call later. The accounts executive was then instructed to transfer money to specified accounts.
Between 3 June and 15 June 2026, the accounts executive allegedly acted on similar WhatsApp instructions.
The complaint alleged that 63 transactions aggregating ₹10,40,71,924 were made.
The fraud reportedly came to light when the accounts executive subsequently approached the actual director seeking invoices relating to the payments and was informed that no such payment instructions had ever been given.
By 20 August, Mumbai Police had reportedly arrested 10 persons in connection with the investigation.
Police also seized 161 SIM cards from two accused who were alleged to have supplied SIM cards used by Boss Scam operators.
From an internal financial-control perspective, the reported 63 transactions over nearly two weeks are especially significant.
Controls should therefore not operate only when a beneficiary is initially created. Repeated, unusual or high-value transfers must themselves generate exception alerts and independent verification.
₹6.8 crore Jaipur fraud shows conversation history itself may be manipulated
A further major incident was reported from Jaipur in August and September 2026.
According to Rajasthan Police, cybercriminals allegedly gained access to a company’s computer system and hijacked the WhatsApp identity of a company director.
Police alleged that the fraudsters blocked the genuine director’s number on WhatsApp Web, saved another number using the director’s name and profile photograph, and recreated earlier WhatsApp conversations with the company’s accounts head.
The accounts head was then allegedly persuaded to transfer ₹6.8 crore into three bank accounts.
Police said none of the company’s directors had authorised the transactions.
The alleged proceeds were subsequently moved through mule accounts and various channels including ATMs, cheques, UPI, QR codes and digital wallets before being converted into USDT cryptocurrency, according to police. Six persons had been arrested by early September.
The investigation continued thereafter. On 18 September, another person was reportedly arrested in Bhubaneswar in a joint operation involving Rajasthan and Odisha Police in connection with the same ₹6.8 crore fraud.
This case demonstrates why checking a display name, profile photograph or even apparent previous WhatsApp conversation history may no longer constitute reliable authentication.
Boss Scam is not confined to WhatsApp
Another subsequent development is important for companies using workplace collaboration platforms.
The basic fraud technique can migrate beyond WhatsApp.
In July 2026, The Indian Express reported that the CFO of an Italian engineering company’s Pune operations received a Microsoft Teams message from a profile carrying the name and photograph of the company’s Italian CEO.
The CFO transferred ₹56 lakh to two accounts.
When a further instruction seeking another ₹1.5 crore arrived the next morning, the CFO became suspicious and independently contacted the actual CEO. That verification prevented the additional transfer.
Another Pune engineering company subsequently reported losing ₹30 lakh after a fraudster allegedly impersonated a director through Microsoft Teams and instructed an employee to make a payment.
The practical lesson is therefore broader than “do not trust WhatsApp”.
No messaging or collaboration platform should, by itself, constitute authority for a material corporate payment.
The common control failure: communication becomes payment authority
The ₹7.8 crore Delhi case, ₹10.4 crore Mumbai case and ₹6.8 crore Jaipur case arose from different factual circumstances and remain subject to their respective investigations.
However, collectively they illustrate an important corporate-control risk:
A communication channel can effectively become the payment-authorisation mechanism unless the company deliberately separates communication from authorisation.
For internal-control purposes:
Communication: WhatsApp, e-mail, Teams, telephone or another platform may communicate that a payment is required.
Authorisation: The company’s approved financial-control process must independently establish that the transaction has actually been authorised.
The first should never substitute for the second.
A WhatsApp account can be compromised. An e-mail account can be compromised. A display photograph can be copied. A contact can be altered. An internal communication profile can be impersonated. Even previous conversation history may potentially be accessed or reconstructed.
Accordingly, the apparent authenticity of a digital communication cannot, by itself, establish valid financial authorisation.
Controls CFOs and finance teams should implement immediately
MHA specifically advises companies to independently verify — through a direct voice call or in-person confirmation — any urgent fund-transfer instruction or account-change request received through WhatsApp or e-mail before acting upon it.
Companies should incorporate this principle into their formal payment-control framework.
Important controls include:
- Maker-checker or dual authorisation: Material payments should require approval by more than one authorised person.
- Independent verification: High-value or unusual payment instructions received through WhatsApp, e-mail or messaging platforms should be verified through a separate channel.
- Previously established contact details: Verification calls should be made to a telephone number already held in the company’s records, rather than a number provided in the suspicious instruction.
- New-beneficiary controls: Creation of a new beneficiary or change in bank-account details should require independent verification.
- Exception reporting: Multiple transfers, unusually high payments, round-sum payments or transactions inconsistent with historical business patterns should generate escalation.
- No urgency override: Statements such as “I am in a meeting”, “don’t call me”, “this is confidential”, “complete immediately” or “I’ll explain later” should increase the level of verification rather than permit normal controls to be bypassed.
- Bank-warning escalation: If the company’s bank itself questions a transaction, the payment should be independently revalidated with the actual authorised person.
- Beneficiary whitelisting: Companies with significant transaction volumes may consider maintaining approved beneficiary lists.
- Cooling period: Depending upon business requirements and banking facilities, enhanced scrutiny or a cooling mechanism may be considered for newly added high-value beneficiaries.
- Emergency-payment documentation: Exceptional transactions should be properly documented and subjected to prompt post-transaction review.
These are risk-control recommendations arising from the modus operandi and reported cases; they should not be confused with specific requirements prescribed by SEBI’s press release.
Important audit and internal-audit implications
The Boss Scam also has implications for statutory auditors, internal auditors, CFOs and audit committees because it tests both the design and operating effectiveness of controls over payments.
Internal audit should examine whether management instructions received outside the ERP or formal payment workflow can effectively override established controls.
An important question is whether dual approval provides genuine independent protection.
Suppose two finance employees approve a ₹2 crore transaction, but both approvals are based entirely upon the same compromised WhatsApp message purportedly sent by the CEO.
Technically, two persons may have approved the payment.
Substantively, however, both approvals may rely upon the same unauthenticated source.
Companies should therefore examine whether their maker-checker framework includes independent authentication of the underlying payment instruction, particularly for exceptional or high-value transactions.
Audit committees and management may also consider controlled simulations in which finance personnel receive an apparently urgent instruction from senior management requesting an exceptional payment. Such exercises can test whether employees actually follow prescribed verification procedures when confronted with realistic urgency and apparent senior-management authority.
Cybersecurity and financial controls must operate together
The Boss Scam demonstrates why cybersecurity controls and financial controls cannot operate in separate silos.
Endpoint protection, anti-malware systems, restrictions on executable files, monitoring of WhatsApp linked devices and blocking malicious infrastructure address the technology side of the attack.
Payment authorisation, maker-checker controls, beneficiary verification and independent confirmation address the financial side.
Neither should be treated as sufficient by itself.
An antivirus product may fail to identify a new malware variant.
Equally, an employee may receive a convincing impersonation message without any malware being installed on the company’s system.
The payment-control environment should therefore be designed on the assumption that, at some point, an employee may receive an extremely convincing but fraudulent instruction appearing to originate from senior management.
Technical precautions recommended by I4C
I4C has advised citizens and organisations not to download, extract or open ZIP files or executable files received from unknown or unverified sources.
It has specifically cautioned that regulators such as RBI do not distribute software updates, security fixes or account statements through WhatsApp attachments.
Organisations should also regularly review:
WhatsApp → Settings → Linked Devices
and terminate WhatsApp Web sessions that are no longer actively required.
System administrators have been advised to enforce software-restriction policies preventing unknown .exe and .dll files from executing from user-profile directories and to ensure that Windows endpoints have updated anti-malware protection.
What should be done if the malicious file has already been opened?
Where a suspicious ZIP or executable file has already been opened, merely deleting the WhatsApp message is not sufficient.
I4C advises an affected user to:
- immediately log out of all linked WhatsApp devices;
- inform contacts not to open files recently received from the compromised account; and
- scan the affected computer using updated anti-virus software.
The organisation should simultaneously involve its IT/cybersecurity team so that the affected endpoint and any wider corporate-network exposure can be examined.
If money has already been transferred, the company’s bank and cybercrime authorities should be contacted immediately.
Speed is particularly important because cyber-fraud proceeds may rapidly be dispersed across multiple mule accounts.
Report financial cyber fraud immediately on 1930
Cyber financial fraud and suspicious communications should be reported immediately through the National Cyber Crime Helpline — 1930 or the National Cyber Crime Reporting Portal.
National Cyber Crime Reporting Portal
The importance of immediate reporting is supported by the wider I4C financial-fraud interception mechanism. In an August 2026 Parliamentary response, MHA stated that its Citizen Financial Cyber Fraud Reporting and Management System had helped save more than ₹11,158 crore across over 32.80 lakh complaints up to 30 June 2026.
Timeline: From emerging warning to multi-crore corporate fraud risk
The developments during 2026 demonstrate how rapidly the threat evolved.
22 June 2026: I4C formally warns about regulatory and executive impersonation using malicious Windows executables and WhatsApp takeover.
June 2026: The ₹7.8 crore Delhi case demonstrates the potential scale of CEO impersonation fraud, with ₹4 crore subsequently frozen.
17 July 2026: SEBI issues PR No. 40/2026, specifically cautioning regulated entities and listed companies about the Boss Scam.
July 2026: A Pune CFO reportedly loses ₹56 lakh to an impersonator using Microsoft Teams but prevents a further ₹1.5 crore transfer after independently contacting the actual CEO.
7 August 2026: MHA reports a sharp rise in complaints, says more than 58,000 potential victims were alerted in the preceding 30 days and reports that more than 10,000 Indians had been protected through coordinated interventions.
20 August 2026: Mumbai Police’s reported arrests in the ₹10.4 crore INOX investigation reach 10; the complaint concerned 63 alleged transfers based on purported senior-management instructions.
23 August 2026: Another Pune engineering company is reported to have lost ₹30 lakh through a Boss Scam conducted over Microsoft Teams.
August–September 2026: Rajasthan Police investigate the ₹6.8 crore Jaipur fraud in which criminals allegedly manipulated WhatsApp identity and earlier conversations; further arrests followed in September.
Conclusion: ‘Boss said so’ cannot be a financial control
The development of the Boss Scam from I4C’s June warning to SEBI’s July intervention and MHA’s expanded August advisory demonstrates that the threat is no longer merely an IT-security issue.
It is simultaneously a cybersecurity risk, fraud risk, internal financial-control risk and corporate-governance issue.
The subsequent ₹7.8 crore Delhi case, ₹10.4 crore Mumbai case and ₹6.8 crore Jaipur case demonstrate the commercial consequences that can follow when apparent senior-management instructions are accepted without sufficiently independent authentication.
The most important control principle is therefore simple:
No WhatsApp message, e-mail, Microsoft Teams message or other digital communication — even one apparently originating from the genuine CEO, MD, promoter, director, CFO or client — should by itself constitute sufficient authority for a material fund transfer.
For boards, audit committees, CFOs, Chartered Accountants, internal auditors and finance teams, cybersecurity controls must be combined with robust payment authorisation and independent verification.
When criminals can compromise or convincingly imitate the identity of the boss, the final defence is a financial-control system that does not depend upon identity appearing genuine on a screen.
Official sources: I4C/MHA Advisory dated 22 June 2026 · SEBI Boss Scam Caution — PR No. 40/2026 · MHA/I4C Expanded Advisory dated 7 August 2026






