
Hyderabad, June 24: The Telangana Cyber Security Bureau (TGCBS) has issued a warning to citizens, government departments, public sector organizations, private companies, and business institutions about a new trend in cyber fraud known as the ‘Boss Scam’ or CEO impersonation fraud.
TGCBS Director Shikha Goyal stated that according to an advisory from the Indian Cyber Crime Coordination Centre (I4C), cybercriminals are targeting senior executives, government officials, business owners, and organizational leaders by sending dangerous files disguised as important regulatory or compliance messages via email and WhatsApp.
In a statement released on Wednesday, she noted that over 300 complaints have been registered across the country in just 20 days, indicating a rapid increase in such incidents.
Explaining how this scam operates, she mentioned that fraudsters send emails or WhatsApp messages containing harmful zip/RAR files. These files are presented as compliance documents, notices, or essential information. Once opened, malware is installed on the victim’s device, granting unauthorized access to active web WhatsApp sessions and other sensitive information.
Subsequently, cybercriminals impersonate senior officials and send fraudulent instructions to employees or finance teams, pressuring victims to transfer money immediately or share confidential information.
According to the TGCBS Director, sudden zip/RAR attachments, messages labeled ‘urgent compliance’ or ‘immediate action required,’ requests for confidential financial transactions, instructions received solely via email or WhatsApp, requests to bypass established approval processes, and pressure to act without verification are all red flags indicating potential threats.
She recommended security measures such as confirming financial instructions through direct phone calls or official communication channels. Users should avoid opening suspicious attachments or files from unknown or unverified sources. Regularly check active web WhatsApp sessions and log out from devices that are not in use. Whenever possible, enable multi-factor authentication (MFA). Follow established organizational approval processes for financial transactions and conduct regular cyber awareness training for employees.
Leave a Comment