A fake WhatsApp message from a senior executive can now be more than a simple impersonation scam. Cybercriminals are combining social engineering with malware to first compromise an employee’s computer and then use trusted corporate communications to push fraudulent financial instructions.
The Indian Cyber Crime Coordination Centre (I4C) has repeatedly warned about this emerging “Boss Scam”, in which criminals impersonate CEOs and senior executives or compromise their actual WhatsApp accounts. In August, I4C said it had alerted more than 58,000 potential victims and helped protect over 10,000 people from a campaign involving malicious files disguised as account statements and regulatory communications.
The uploaded cybersecurity advisory highlights the central danger: reporting a financial fraud does not necessarily end the incident. If an employee has opened or executed a suspicious attachment, the computer itself may remain compromised.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
How the two-stage “Boss Scam” actually works
The first stage is psychological. A criminal pretends to be the boss or senior officer and creates urgency, authority and secrecy to make an employee transfer money, reveal information or open a file.
The second stage is technical. The attacker sends a malicious ZIP file, document, link, APK or other attachment. If the victim opens or executes it, malware can establish access to the computer and potentially expose credentials, active sessions and organisational data.
That distinction is important. An employee may believe they have simply fallen for a payment scam, while the attacker may still have access to the device used to carry out the transaction.
I4C has described a similar campaign in which malicious ZIP archives are presented as urgent communications from the RBI, Ministry of Corporate Affairs or other authorities. When extracted and opened on a Windows computer, the files can install malware and compromise an active WhatsApp Web session.
Why a trusted WhatsApp account makes the scam dangerous
WhatsApp is particularly useful to fraudsters because employees already trust messages from their colleagues and senior officers.
Once an account or WhatsApp Web session is compromised, criminals can potentially communicate with the victim’s existing contacts. They can then use the credibility of that account to send further files or request urgent payments.
I4C has warned that compromised accounts can be used to circulate the same malicious file to contacts and groups. This can turn one infected computer into a pathway for reaching several other employees and potentially spreading the compromise through an organisation.
The tactic has already appeared in major Indian fraud investigations. In a Delhi case involving an alleged ₹7.8 crore corporate fraud, investigators found that a malicious ZIP file was initially sent to a company director before the compromised account was used to impersonate a senior executive and instruct an accountant to transfer funds.
The420.in has also reported a separate Mumbai case in which a corporate accounts executive was allegedly tricked into transferring more than ₹10.40 crore after fraudsters impersonated a senior company official on WhatsApp.
Opening the file changes the response completely
The cybersecurity advisory makes a crucial distinction between the financial fraud and the possible computer compromise.
If an employee only receives a suspicious message, it can be reported and deleted without opening the attachment. But if the file has already been opened or executed, the affected computer should be treated as a separate cyber-security incident.
The recommended response is to stop using the computer for sensitive work and immediately inform the organisation’s IT or cyber-security team. Employees should avoid logging into banking systems, email, VPNs or cloud services from that device until it has been assessed.
Security teams also need to determine exactly what happened. A file being downloaded is different from being opened, extracted or executed. Investigators may need the filename, timestamp, device information, network activity and other digital evidence to establish whether the attacker gained further access.
Deleting the suspicious file immediately can therefore be counterproductive. The advisory specifically cautions against randomly deleting files, running unapproved cleaning tools or formatting the computer before security or forensic teams have assessed it.
The biggest weakness is still human trust
The scam works because the criminal does not necessarily need to defeat sophisticated security software at the beginning.
They need an employee to believe that the message is genuine.
The advisory therefore recommends independent verification for urgent payment instructions, especially when a new beneficiary or bank account is involved. Employees should call the senior officer using a known number rather than confirming the instruction through the same WhatsApp conversation.
Companies are also being urged not to treat early reporting as an employee failure. The advisory says workers should be encouraged to immediately report that they opened a suspicious file, because early reporting can prevent one compromised computer from becoming a wider organisational incident.
For banks, the warning has another implication. When an unusual corporate transfer follows an apparently legitimate senior-officer instruction, the possibility of a compromised communication channel or endpoint should also be considered.
The basic rule is simple: verify the person, do not execute the file and report the technical incident separately from any financial loss. A suspicious attachment may be an attempted fraud, but once it has been opened, it may also be an attempted break-in.
What this means for you: If your boss suddenly asks you on WhatsApp to make an urgent payment, do not rely on the profile photograph, name or even a familiar-looking account. Verify the instruction through an independent channel, and never open an unexpected ZIP, executable, APK or document simply because the sender appears to be someone you know.
If you have already opened a suspicious attachment, stop using that computer for sensitive work and immediately alert your IT or cyber-security team. If money has also been transferred, contact your bank and report the financial fraud through 1930 without delay. Most importantly, tell the security team that you opened the file; reporting only the financial loss may leave the underlying computer compromise undiscovered.