Date : Aug-11-2026
The Indian Cyber Crime Coordination Centre (I4C), which works under the Ministry of Home Affairs, has issued a warning for companies, finance professionals, and businesspeople about a new and dangerous online scam. This scam works by taking over people's WhatsApp accounts using harmful files that look like bank statements or official messages from government departments.
The Ministry said that I4C has seen a big rise in complaints on the National Cyber Crime Reporting Portal (NCRP) about WhatsApp accounts being hacked. Similar cases have recently come up in Delhi, Gujarat, Maharashtra, and Rajasthan. I4C had first warned people about this threat through an advisory issued on June 22, 2026.
The scam usually starts when a person receives a compressed zip file through WhatsApp, SMS, or email. These files often have names like "Statement of Account.zip," "RBI.zip," or "MCA.zip." In some cases, the scammers also pretend to be from the Income Tax Department and send fake emails.
The message attached to the file looks like a normal bank statement or an urgent notice from regulators such as the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA). When the file is opened on a Windows computer, it installs harmful software (malware) on the device. This malware takes control of the person's WhatsApp Web session.
Once the account is hacked, the scammers use it to send the same harmful file to the victim's contacts and WhatsApp groups automatically. The message usually asks the receiver to forward the file to their company's finance manager and to open it on a computer, which helps the scam spread further.
I4C explained that this scam often turns into what is known as the "Boss Scam" or "CEO fraud." In this type of fraud, criminals use the hacked WhatsApp account of a senior company officer, or pretend to be the CEO, to tell finance staff to transfer money urgently to fake bank accounts.
According to technical checks done by the National Cybercrime Threat Analytics Unit (NCTAU), this scam is being run by organised cybercriminal groups from other countries. They use advanced malware that can hide from antivirus programs using a method called DLL sideloading. The case is being investigated with the help of police and technical experts.
The advisory said that Chartered Accountants, Company Directors, Chief Financial Officers (CFOs), and finance staff are at high risk, since the malware only works on Windows computers and the fake messages are made to look like real financial matters.
The Home Ministry has asked companies to make their employees, especially finance teams, aware of this scam. It also advised that any urgent message asking for money transfers or bank account changes through WhatsApp or email should be checked by making a phone call or talking in person before taking any action.
To fight this threat, I4C said it has been warning possible victims identified through complaints and technical information, so they can secure their accounts by logging out of other linked devices and taking safety steps.
The Centre has also shared technical details about the malware with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender, and Indian cybersecurity companies like Quick Heal, K7 Computing, and Net Protector, so that the harmful files can be detected and blocked quickly.
The Ministry said these efforts have already protected more than 10,000 citizens from this scam. The malware linked to the fraud is also being blocked through the Sahyog Portal.
I4C added that it has sent warning messages to more than 58,000 possible victims in the last 30 days using the SMS sender ID "I4CMHA-G." People have been asked to pay attention to such messages and follow the safety steps mentioned in them.
The Ministry has advised people not to download or open zip files or executable files sent by unknown or unverified sources. It also reminded users that regulators like the RBI never send software updates, security patches, or account statements through WhatsApp attachments.
Users have been asked to regularly check and remove old or inactive WhatsApp Web sessions from the "Linked Devices" section of the app. Companies have also been advised to set up software restriction rules and make sure all Windows computers have updated anti-malware protection.
The Ministry urged everyone to immediately report any cyber fraud or suspicious messages by calling the National Cyber Crime Helpline at 1930, or by using the National Cyber Crime Reporting Portal.
Source: https://ddnews.gov.in