The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, has issued an advisory warning corporates, finance professionals and businesspersons against a sophisticated cyber fraud campaign involving the takeover of WhatsApp accounts through malicious files disguised as account statements and regulatory communications.
According to the Ministry of Home Affairs, I4C has observed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) related to WhatsApp account compromises. Similar incidents have recently been reported from Delhi, Gujarat, Maharashtra and Rajasthan. The Centre had earlier flagged the emerging threat through an advisory issued on June 22, 2026.
The fraud begins with victims receiving compressed .zip files via WhatsApp, SMS or email bearing names such as “Statement of Account.zip”, “RBI.zip” or “MCA.zip”. In some cases, cybercriminals also impersonate the Income Tax Department through emails.
The accompanying message is designed to appear as either a routine account statement or an urgent compliance notice from regulators such as the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA). Once the file is extracted and opened on a Windows computer, malware is installed that compromises the device and hijacks the victim’s active WhatsApp Web session.
The compromised WhatsApp account is then used to automatically circulate the same malicious file to the victim’s contacts and groups, often with a message requesting recipients to forward it to their company’s finance manager and open it on a desktop or laptop, thereby spreading the infection.
According to I4C, the fraud often progresses into what is commonly known as the “Boss Scam” or CEO impersonation fraud, in which cybercriminals use the compromised WhatsApp account of a senior executive—or impersonate the CEO—to instruct finance personnel to make urgent transfers of funds to fraudulent bank accounts.
Technical analysis by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C indicates that the campaign is being operated by organised cross-border cybercriminal networks using advanced malware capable of evading detection through DLL sideloading techniques. The matter is being investigated in coordination with law enforcement and technical agencies.
The advisory said the campaign poses a particularly high risk to Chartered Accountants, Company Directors, Chief Financial Officers (CFOs) and finance and accounts personnel, as the malware is activated only on Windows systems and the fraudulent messages are tailored to financial operations.
The Home Ministry urged organisations to sensitise employees, particularly finance teams, and verify any urgent request for fund transfers or changes in bank account details received through WhatsApp or email by making a direct voice call or confirming the instruction in person before acting on it.
To counter the threat, I4C said it has been proactively alerting victims and potential targets identified through complaint analysis and technical intelligence, enabling them to secure their accounts by logging out of linked devices and taking remedial measures.
The Centre has also shared technical indicators of the malware with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender, and leading Indian cybersecurity firms, including Quick Heal, K7 Computing and Net Protector, to facilitate rapid detection and blocking of malicious files.
According to the Ministry, these coordinated efforts have protected more than 10,000 citizens from the campaign so far, while malware linked to the fraud is being blocked through the Sahyog Portal.
I4C further said it has sent alerts to over 58,000 potential victims in the past 30 days through the SMS header “I4CMHA-G” and advised citizens to pay attention to such messages and follow the security instructions provided.
The Ministry has advised citizens not to download or open .zip files or executable files received from unknown or unverified sources. It also reminded users that regulators such as the RBI do not send software updates, security patches or account statements through WhatsApp attachments.
Users have also been advised to regularly review and remove inactive WhatsApp Web sessions under the Linked Devices section, while organisations should implement software restriction policies and ensure that all Windows systems are protected with updated anti-malware software.
The Ministry urged citizens to immediately report cyber fraud or suspicious communications by calling the National Cyber Crime Helpline 1930 or through the National Cyber Crime Reporting Portal.




