I4C Warns Companies About Malware-Driven 'Boss Scam' Targeting Executives
India's cybercrime coordination body has flagged a 'Boss Scam' in which fraudsters impersonate senior executives, hijack WhatsApp sessions and push finance teams into urgent money transfers.
Commentary & Analysis ·

The Indian Cyber Crime Coordination Centre (I4C) has warned companies about a 'Boss Scam' in which fraudsters impersonate senior executives or regulators to pressure staff into urgent money transfers. Reports on 22 June 2026 said the fraud blends social engineering, malware and workplace hierarchy into a single, fast-moving attack. What makes this advisory notable is not that impersonation fraud is new, but that it has evolved into something far harder to catch: an attack that combines a technical breach with an exploitation of the very obedience that keeps corporate hierarchies functioning.
How the scam works
According to the advisory, attackers may send malicious archive files through email or WhatsApp, disguising them as compliance or official documents. Once a target opens the file, the malware can compromise Windows devices and hijack active Web WhatsApp sessions. From inside a hijacked account, the criminals message finance teams while appearing to be a genuine senior official, lending the request the authority of the chain of command and making a hurried transfer feel routine.
This is a meaningfully different attack chain from the older, cruder forms of impersonation fraud that many companies believe they have already guarded against. Traditional phishing relies on a spoofed email address or a lookalike domain name, both of which alert employees have been trained for years to scrutinise. Here, the entry point is not a fake identity at all but a genuinely hijacked one. Because the message originates from the real WhatsApp account of a real senior executive, the usual red flags, an unfamiliar number, a misspelt name, an odd sender address, simply do not appear. The victim is not being asked to trust a stranger; they are being asked to trust their own boss, using their own boss's actual account.
Why companies are vulnerable
The danger lies in the combination. Technical compromise gives the attacker a trusted identity, while the psychology of hierarchy discourages a junior employee from questioning what looks like a direct instruction from the top. Urgency is engineered deliberately to short-circuit normal checks. Finance and accounts teams are the prime targets because they can authorise payments, and a single unverified transfer can move large sums before anyone notices the deception.
This vulnerability is structural rather than incidental. Most organisations, particularly larger ones with layered management, are built around the assumption that instructions flowing down from senior figures should be acted upon promptly and without friction. That assumption is precisely what the Boss Scam turns into a weapon. An employee who receives what appears to be an urgent, time-sensitive request from a superior faces a genuine dilemma: querying the instruction risks being seen as insubordinate or obstructive, while complying risks enabling fraud. Scammers understand this tension well, which is why urgency is not incidental to the scheme but central to it. A request framed as routine, with time to check, invites scrutiny. A request framed as urgent, confidential and time-critical does not.
The wider implications for Indian businesses
The I4C's warning arrives at a moment when Indian companies, across sectors from manufacturing to IT services, have become heavily reliant on WhatsApp as an informal but ubiquitous channel for internal communication, including instructions that touch on payments and approvals. That reliance is precisely what creates the opening this scam exploits. Where a formal, auditable communication channel might force a paper trail and a moment's pause, an instant message on a familiar platform, appearing to come from a known number, collapses that pause into nothing at all. The convenience that made WhatsApp indispensable in the first place is the same convenience the fraud is designed to abuse.
There is also a broader lesson here about how cybercrime in India is maturing. Earlier generations of financial fraud tended to rely on relatively unsophisticated tricks, fake calls claiming to be from banks, or poorly worded phishing emails, that alert staff could often spot. The Boss Scam represents a more advanced fusion of malware deployment, session hijacking and social engineering, suggesting that the people behind these schemes are investing in both technical capability and a genuine understanding of corporate behaviour. That combination should concern security teams more than either element would on its own.
How to protect against it
The I4C has urged firms to build verification habits that do not depend on a single channel, and to treat unexpected payment instructions, however senior the apparent source, with caution. Its recommendations include verifying all payment instructions through a second, independent channel; avoiding opening unknown executable or archive files from email or WhatsApp; training finance and accounts teams to recognise urgency-based pressure; securing and regularly reviewing Web WhatsApp and other active sessions; and reporting suspected cybercrime quickly through official channels.
None of these measures is technically complex, and that is rather the point. The advisory is not asking companies to deploy some exotic new security tool; it is asking them to institutionalise a habit, treating a second channel of confirmation as mandatory rather than optional, however inconvenient that feels in the moment an urgent-sounding message arrives. As the I4C advisory put it, as reported, "Firms are being urged to verify payment instructions through a second channel and to report suspicious activity quickly." That single sentence captures the entire defensive posture the advisory is pushing companies towards.
As impersonation tactics grow more technically sophisticated, the most reliable defence remains procedural: a culture in which verifying an unusual payment request is expected rather than awkward. For Indian companies, the I4C warning is a prompt to harden both their software and their habits. Technical hygiene, keeping devices patched, monitoring active WhatsApp Web sessions, restricting who can open unsolicited archive files, will reduce the odds of compromise in the first place. But even the best technical defences will not stop every intrusion, which is why the human layer of verification matters just as much, if not more.
The NE Times View
The 'Boss Scam' weaponises hierarchy itself, exploiting the instinct to obey a senior's urgent order. As fraud shifts from crude phishing to hijacked WhatsApp sessions, India's real vulnerability is cultural as much as technical: finance teams trained to comply, not question. I4C's alert is useful, but defence lies in dull discipline, payment verification protocols, callback rules and a workplace where double-checking the CEO is rewarded, not punished.
What deserves emphasis is that this is ultimately a management problem dressed up as a technology problem. Firms can install every patch and monitor every session, yet still fall victim if a junior employee feels unable to pause and ask a second question of someone who appears to outrank them. Building that permission into the culture, explicitly telling finance staff that querying an urgent transfer instruction will never be held against them, may do more to blunt this scam than any single piece of software. The I4C's advisory should be read by company leadership not merely as an IT bulletin to be forwarded to the security team, but as an instruction to examine how authority and urgency interact inside their own organisations.
Key takeaways
- The I4C has warned of a 'Boss Scam' combining malware, hijacked WhatsApp sessions and impersonation of senior executives to pressure finance staff into urgent transfers.
- Attackers use malicious archive files disguised as compliance documents to compromise Windows devices and take over Web WhatsApp sessions, then message finance teams posing as genuine senior officials.
- The scam is effective because it pairs a technically hijacked, trusted identity with engineered urgency that discourages employees from questioning instructions from apparent superiors.
- The I4C recommends verifying payment instructions through a second independent channel, avoiding unknown archive files, training staff on urgency-based pressure, securing WhatsApp sessions, and reporting incidents promptly.
- Lasting protection depends less on new technology than on a workplace culture where verifying an unusual payment request, even one apparently from the top, is expected rather than discouraged.
You may also like to read

I4C Warns Indian Companies of Rising 'Boss Scam' CEO-Impersonation Cyber Fraud
India's cybercrime coordination agency has flagged an emerging 'Boss Scam' in which fraudsters impersonate regulators and executives to push urgent, fraudulent money transfers at companies.

Telegram Faces Growing India Scrutiny After Home Ministry Cybercrime Report
Telegram is under sharper scrutiny in India after a Home Ministry cybercrime report flagged the platform's alleged use for child sexual abuse material and financial fraud across its largest market of 150 million-plus users.

India Steps Up Telegram Monitoring Over Cybercrime And Fraud Concerns
India's cybercrime agencies are proactively monitoring Telegram groups and channels linked to fraud and illegal content, as the government balances citizen safety against lawful digital communication.

Centre Warns Telegram on Piracy in Platform Accountability Drive
The government has issued a stern warning to Telegram over pirated films, books and exam material circulating on the app, sharpening India's push to hold digital platforms accountable for unlawful content.
More from this section
MoreCG Semi Sanand Plant Opens, Boosting India's Semiconductor Drive
Prime Minister Narendra Modi inaugurated CG Semi's chip assembly and test facility in Sanand, Gujarat, giving India's semiconductor mission a working manufacturing milestone rather than another policy promise.

Chinese E-Rickshaw Apps Banned in India Over Remote Disable Risk
The Centre has ordered the removal of three Chinese apps — BAT-BMS, Lossigy and Epoch-i-ion — over fears they could remotely disable battery-run e-rickshaws, turning mobility software into a public safety concern.

Connected Car Rules: India Plans Vehicle Software Update Norms
With cars increasingly run by software, the government is reportedly preparing update and security norms aimed at preventing vehicle hijacking and governing how connected cars in India are patched and protected.