Operational risk is on the up for corporate finance desks in India as bad actors take over WhatsApp accounts to pose as top brass and demand prompt fund transfers. The Ministry of Home Affairs says the Boss Scam is picking up pace, with Microsoft Teams and email being put to similar use to funnel high-value payments into mule accounts.
Why this scam is a material risk for companies
The threat is one of approval integrity. When cybercriminals get hold of an executive’s WhatsApp Web session they can put forward payment instructions that seem perfectly routine and time-sensitive to the finance staff.
Investors would see this as exposure to cash leakage, delays in reconciliation and damage to reputation. The ministry has identified finance as the function most at risk and called for independent checks before acceding to urgent demands.
How the attack unfolds across WhatsApp and Teams
The Indian Cyber Crime Coordination Centre reports that criminals are passing off malicious files as MCA or RBI documents, or a Statement of Account. These come in the form of compliance notices over SMS, email or WhatsApp that require immediate action.
A senior police officer noted fraudsters are also using Microsoft Teams to impersonate a CEO or MD and order an employee to move money. His advice is not to go through with an urgent bank transfer or change of account without speaking to the person in question directly or in person.
From malware drop to WhatsApp Web hijack
The National Cybercrime Threat Analytics Unit has found that organised cross-border groups are making use of the DLL sideloading technique to deploy sophisticated malware on Windows devices.
Open a malicious ZIP archive and a Trojan will have compromised the system, giving the user’s active WhatsApp Web session over to the attacker. From there they can send the same files to the victim’s contacts and groups, putting pressure on them to pass it along to the company’s finance manager.
Scale of alerts and official response
Complaints have been mounting on the National Cyber Crime Reporting Portal from places like Delhi, Gujarat, Rajasthan and Maharashtra, prompting the alert. Law enforcement and technical agencies are now investigating.
I4C has been proactive in reaching out to those at risk and sharing indicators of compromise with CERT-In, Microsoft Defender and local cybersecurity firms. Coordinated interventions have shielded more than 10,000 Indians. In the last 30 days alone, SMS from the ‘I4CMHA-G’ header have put over 58,000 potential victims on notice.
The ministry put out a further advisory to confirm these numbers, saying over 10,000 users have been protected and 58,000 alerted in the past month under the ‘I4CMHA-G’ banner. An earlier notice from the centre on June 22, 2026, was more specific, detailing Regulatory and Executive Impersonation for the purpose of High-Value Financial Fraud via WhatsApp Account Takeover with Malicious Windows Executables.
Immediate controls finance leaders should enforce
Both I4C and the ministry are telling organisations to put some brakes on approval workflows when messages come in through unorthodox channels and to harden their first-line defences. As for regulators like the Reserve Bank of India, they do not send out software patches or account statements as WhatsApp attachments.
To limit exposure, the following should be considered priority actions:
– A direct phone call to verify anything urgent
– No opening of executable or ZIP files from an unknown source
– Regular review of Linked Devices on WhatsApp
– Log out of any inactive WhatsApp Web sessions
– Put a block on the execution of unknown .exe and .dll files
– Ensure anti-malware is current
Should a compromise be suspected, the computer needs to be scanned with updated antivirus and the user must log out of every linked device and let contacts know not to open files from the account in question. The ministry has also pointed to cases where phishing emails have been used to stand in for the Income Tax Department.
One police officer was at pains to point out how attackers make use of trust and a sense of urgency to pull off financial fraud. He suggested training on message-origin and maker-checker rules for payments can be a way to stop the scam in its tracks.
Any suspected incident should be reported to the National Cyber Crime Helpline on 1930 or via the portal. I4C would have users and administrators view any unverified file purporting to be from the RBI, MCA or a Statement of Account with suspicion.











