4 states hit as WhatsApp 'Boss Scam' hijacks accounts via .zip files
A new wave of WhatsApp-based CEO impersonation fraud is spreading across India using malicious .zip files that hijack executive accounts and auto-propagate through contact lists. The Indian Cybercrime Coordination Centre warns of a sharp rise in complaints.
Key Takeaways
- A new wave of WhatsApp-based CEO impersonation fraud is spreading across India using malicious .zip files that hijack executive accounts and auto-propagate through contact lists.
- The Indian Cybercrime Coordination Centre warns of a sharp rise in complaints.
Mentioned
Key Intelligence
Key Facts
- 1The 'Boss Scam' involves malicious .zip files (e.g., '0714 Statement of Account.zip', 'RBI.zip', 'MCA.zip') sent via WhatsApp, SMS, or email.
- 2Clicking the file compromises the victim's WhatsApp account and automatically forwards the malware to all contacts, often with a request to send it to the 'company finance manager'.
- 3Fraudsters then use the hijacked WhatsApp account of a senior executive to instruct finance teams to transfer funds to mule accounts (CEO impersonation fraud).
- 4The Indian Cybercrime Coordination Centre (I4C) reported a sharp rise in complaints on the National Cyber Crime Reporting Portal from Delhi, Gujarat, Maharashtra, Rajasthan, and other states.
- 5I4C issued a public warning on 7 August 2026, noting the identical modus operandi across multiple states.
- 6The scam targets professionals and businesspersons, exploiting trust in regulatory communications (RBI, MCA) and urgency around account statements.
The compromised WhatsApp account is misused soon after the victim clicks on a compressed (.zip) file received over WhatsApp, SMS or e-mail... The compromised WhatsApp account is thereafter misused to automatically circulate the same malicious file to all the contacts and groups of the victim, typically with a request to forward the file to the recipient's 'company finance manager for verification' and to open it on a computer, thereby extending the chain of infection deeper into corporate networks.
Public alert issued on 7 August 2026
Analysis
For cybersecurity professionals, the 'Boss Scam' represents a classic social-engineering attack supercharged by WhatsApp's trusted contact model. The use of compressed files with names like 'RBI.zip' and an auto-forwarding mechanism to penetrate corporate finance teams signals a deliberate convergence of malware and business email compromise tactics—now mobile-first. Understanding the attack chain is critical for threat hunters and incident responders.
India's cybercrime watchdog has sounded an alarm over a sharp rise in 'Boss Scam' cases—a WhatsApp-based CEO impersonation fraud that is compromising executive accounts and directing finance staff to transfer funds to mule accounts. The Indian Cybercrime Coordination Centre (I4C), a wing of the Ministry of Home Affairs, observed a sudden spike in complaints on the National Cyber Crime Reporting Portal (NCRP) from Delhi, Gujarat, Maharashtra, Rajasthan and other states, prompting it to issue a public warning on 7 August 2026. The scam begins with a deceptively simple vector: a compressed .zip file with names like '0714 Statement of Account.zip', 'RBI.zip', or 'MCA.zip' sent over WhatsApp, SMS or email. When the recipient clicks on the attachment, their WhatsApp account is immediately compromised. The malware then silently forwards the same malicious file to all contacts and groups, often with a note instructing recipients to pass it on to their 'company finance manager for verification' and to open it on a desktop—thus chaining the infection deeper into corporate networks.
For cybersecurity professionals, the 'Boss Scam' represents a classic social-engineering attack supercharged by WhatsApp's trusted contact model.
The advanced stage of the fraud exploits the hijacked account's authenticity. Fraudsters either use the compromised WhatsApp of a senior executive directly or covertly save an alternate number in victims' contacts under the executive's name, then issue urgent payment instructions to finance teams. Because the messages come from a trusted contact, or appear to, they bypass normal skepticism. The I4C noted that this modus operandi has been widely reported across India's industrial and commercial hubs, indicating a coordinated campaign targeting professionals and business owners. The use of account statements, RBI (Reserve Bank of India) branding, and MCA (Ministry of Corporate Affairs) filenames adds a layer of social engineering that exploits anxiety about regulatory compliance and financial audits.
This fraud pattern mirrors global Business Email Compromise (BEC) and CEO fraud trends but is specifically weaponized for WhatsApp, which dominates business communication in India. The platform's end-to-end encryption and personal nature make it an ideal channel for deception, as employees often treat WhatsApp messages from a boss as inherently trustworthy. The I4C's warning underscores a broader vulnerability: as organizations increasingly rely on instant messaging for financial approvals, the attack surface expands. No technical sophistication in malware is required—just the ability to craft plausible filenames and exploit human psychology. However, the auto-forwarding capability suggests the file may contain a script or malware that accesses WhatsApp Web or the mobile app's permissions, though the source does not detail the technical exploit.
What to Watch
The rising number of complaints on the NCRP—while no exact figures are given—indicates that this scam is achieving a troubling success rate. For businesses, the consequences can be severe: unauthorized wire transfers to mule accounts are often irreversible, and the reputational damage from a compromised executive account can erode client and partner trust. The I4C's proactive alert is a rare move, reflecting both the scale and the potential for escalation. With India's digital payment infrastructure growing rapidly, such scams could undermine confidence in digital financial communications.
Looking ahead, the 'Boss Scam' is likely to evolve. Attacks may incorporate AI-generated voice notes or deepfakes to add authenticity, or pivot to other messaging platforms. Organizations must urgently implement multi-factor verification for financial transactions initiated via messaging, conduct regular security awareness training specifically around WhatsApp threats, and ensure that finance teams confirm any out-of-band payment requests through a secondary channel. The I4C's warning is not just a bulletin—it's a sign that the convergence of social engineering and ubiquitous messaging platforms is reshaping the corporate threat landscape in India.
Timeline
Timeline
I4C issues public warning on 'Boss Scam'
After observing a sharp rise in NCRP complaints, the Indian Cybercrime Coordination Centre alerts the public about WhatsApp-based CEO impersonation fraud spreading across multiple states.
Sources
Sources
Based on 2 source articles- nigeriasun.com Boss Scam reports rising from Delhi , Gujarat , Maharashtra , Rajasthan among other statesAug 7, 2026
- londonmercury.com Boss Scam reports rising from Delhi , Gujarat , Maharashtra , Rajasthan among other statesAug 7, 2026
Cite This Page
"4 states hit as WhatsApp 'Boss Scam' hijacks accounts via .zip files." Cyber Intelligence Brief, August 7, 2026. https://getcyberbrief.com/story/whatsapp-boss-scam-zip-malware-2026
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |