What happened?

The Indian Cyber Crime Coordination Centre (I4C) has issued an advisory warning businesses about a growing cyber fraud known as the ‘Boss Scam’ or CEO impersonation fraud. Fraudsters are sending malicious .zip files through WhatsApp, email, and SMS, disguised as documents such as “Statement of Account.zip”, “RBI.zip”, or “MCA.zip”. When opened on a Windows device, these files can install malware and hijack active WhatsApp Web sessions.

Who could be affected?

The scam primarily targets:

  • Company directors
  • CEOs and senior executives
  • CFOs
  • Chartered Accountants
  • Finance and Accounts teams

Once an account is compromised, fraudsters can impersonate senior officials and send urgent payment instructions to employees, increasing the risk of fraudulent fund transfers.

How can MSMEs protect themselves?

  • Never open unknown .zip, .exe, or .dll files.
  • Verify urgent payment or account change requests through a direct phone call.
  • Regularly review WhatsApp Linked Devices and sign out of unused sessions.
  • Keep antivirus and security software up to date.
  • If your account is compromised, immediately log out of all linked devices and report the incident on 1930 or cybercrime.gov.in.

Why it matters

A payment request received through WhatsApp or email should never be treated as genuine based on the sender’s name alone. Verifying instructions before approving transactions can help MSMEs avoid significant financial losses.

Reference: Press Information Bureau Release