I4C warns corporates of 'Boss Scam' WhatsApp account takeover malware
The Indian Cyber Crime Coordination Centre warned on 7 August 2026 of a 'Boss Scam' in which malicious account-statement and RBI-themed files take over WhatsApp accounts of executives to trick finance staff into transferring money.
Summary
The Indian Cyber Crime Coordination Centre (I4C) of the Home Ministry cautioned corporates and finance professionals on 7 August 2026 against a 'Boss Scam'. In this fraud, self-propagating malware disguised as account statements, MCA or RBI files takes over WhatsApp accounts of senior executives, which are then used to instruct finance staff to transfer funds to mule accounts. Chartered accountants, company directors and CFOs are the prime targets. I4C has alerted over 58,000 potential victims through the SMS header 'I4CMHA-G' in 30 days, and geo-blocking of command-and-control servers through the Sahyog Portal has protected more than 10,000 Indians.
Key facts
- Alert by
- Indian Cyber Crime Coordination Centre (I4C), MHA
- Scam
- 'Boss Scam' – WhatsApp takeover via malicious files
- Targets
- CAs, company directors, CFOs, finance teams
- Victims alerted
- 58,000+ via SMS header 'I4CMHA-G'
- Protected
- 10,000+ via geo-blocking C2 servers on Sahyog Portal
Practice MCQs 2 questions
Which SMS header did I4C use to alert potential victims of the 'Boss Scam' in 2026?
Show answer
Correct answer: D — I4CMHA-G
I4C intimated over 58,000 potential victims through the SMS header 'I4CMHA-G' in 30 days.
Through which portal did geo-blocking of the 'Boss Scam' command-and-control servers protect more than 10,000 Indians?
Show answer
Correct answer: B — Sahyog Portal
More than 10,000 Indians were protected by geo-blocking the C2 servers through the Sahyog Portal.