DEV Community

relayshieldadmin
relayshieldadmin

Posted on Originally published at blog.relayshield.net

The "Boss Scam": When the Message from Your CEO Isn't Your CEO

In August 2026, India's Indian Cyber Crime Coordination Centre (I4C) warned about a rapidly emerging fraud targeting company directors, CFOs, chartered accountants, and finance teams. They call it the "Boss Scam" — and it marks a significant shift in how messaging-app fraud works.

The old CEO impersonation scam was crude: a fraudster created a fake account, slapped your boss's name and profile photo on it, and asked you to approve an urgent payment. It worked often enough to be a problem, but there was usually something off — a new number, slightly wrong spelling, a request that didn't quite fit the company's process.

The new version skips the impersonation entirely. The attackers try to take over the real account.

It begins with a file. It may arrive disguised as a "Statement of Account," an RBI notice, an MCA filing, or income-tax correspondence — the kind of thing a finance team would open without thinking twice. The malicious ZIP contains Windows executables and DLL files. Once opened, the malware can compromise the computer and hijack an active WhatsApp Web session.

That is the part that matters. The fraudster no longer needs to convincingly pretend to be your boss. They can attempt to take over the account your employees already trust — and the trust is what does the work.

The fraud then moves laterally. From the compromised executive's account, the attackers can forward the same malicious file to colleagues, who open it precisely because it came from someone they know. In the final stage, criminals use the genuine or impersonated CEO identity to instruct finance employees to make urgent payments to mule accounts.

The scale is already serious. I4C said it had alerted more than 58,000 potential victims through the SMS header "I4CMHA-G" in the preceding 30 days, and that more than 10,000 people had been protected from the campaign through intervention.

Why this pattern is worth watching closely

What makes the Boss Scam different from most messaging-app fraud is that the lure is not the message — it is the attachment. The attack chain has three links: a trusted-looking business file, a compromised session, and a trusted identity used for lateral spread and payment fraud. Phishing kits and stealer tooling of exactly this kind are routinely advertised in the Telegram marketplaces RelayShield monitors (113 marketplaces tracked), and RelayShield's TI corpus — 7.8M+ citations across 494K+ indicators — follows how these lures evolve, so the patterns behind campaigns like this are visible before they reach your inbox.

RelayShield's WhatsApp bot applies the same principle at the point of contact. It is built around one simple idea: the message arriving from a familiar name is the wrong place to make a trust decision.

One defensive takeaway

Treat every urgent payment instruction arriving by message as unverified — even when it comes from the real account of someone you know. Confirm it through a separate channel (a phone call, a walk down the hall, the company's normal approval flow) before money moves. And if an "invoice" or "statement" file arrives unexpectedly by message, run any links it contains through a scam check first — RelayShield's free link and email checks exist exactly for this. Accounts get hijacked; process doesn't.


Sources: ET Edge Insights roundup of I4C/MHA warnings, "The anatomy of digital deception: 2026's top 5 cyber frauds" (published ~Sep 24, 2026), citing I4C's August 2026 Boss Scam warning. Figures: 58,000+ potential victims intimated via SMS header "I4CMHA-G" in 30 days; 10,000+ protected through intervention.

Top comments (0)