WhatsApp “Boss Scam” Alert: How the New AI-Powered Scam Works

A message arrives from your CEO on WhatsApp. It’s urgent, it’s confidential, and it’s asking you to transfer money right now. The profile photo matches. Maybe there’s even a voice note that sounds exactly like them. Everything about it looks real — because in some versions of this scam, it actually is coming from your boss’s real, hijacked WhatsApp account.

India’s cybercrime agency, the Indian Cyber Crime Coordination Centre (I4C), and market regulator SEBI have both issued formal alerts this year about a fast-spreading fraud they’re calling the “Boss Scam” — a significant evolution of the classic CEO impersonation scheme, supercharged by AI and a cleverer distribution method than fraudsters have used before.

Here’s exactly how it works.

Two different attack methods, one goal

SEBI’s advisory breaks the scam into two distinct tactics, and it’s worth understanding both, because they require different defenses.

Method one: AI impersonation

Fraudsters use AI voice cloning, deepfake video calls, and fake social media groups to convincingly imitate a CEO or managing director. They message finance or accounts employees — through WhatsApp, email, or other platforms — creating a fake but highly convincing version of a senior executive. In some documented cases, attackers who’d already compromised a device went a step further: they saved their own phone number under the CEO’s or MD’s name in the victim’s contact list, so any incoming call or message would display the boss’s name automatically.

Method two: the malware route — and the scarier one

This is the version that makes the “Boss Scam” genuinely different from older CEO fraud. Fraudsters send a compressed .zip file to a target — often a finance officer — through a message. If that file is opened on a Windows computer, it installs malware that hijacks the person’s active WhatsApp Web session. From there, attackers gain real, live control of that employee’s actual WhatsApp account.

Once inside, they don’t need to fake anything. They use the hijacked account — which might belong to a senior executive — to send legitimate-looking payment instructions directly to other employees. Because the message is coming from a real, verified account that colleagues already trust, it sails past exactly the kind of red flags employees have been trained for years to watch out for.

Why this beats older scam-detection training

Traditional CEO fraud — sometimes called business email compromise (BEC) — relied on tricks employees could be trained to spot: spoofed domains, slightly misspelled sender addresses, odd formatting. The Boss Scam sidesteps all of that. When the message comes from a genuinely hacked account, there’s no fake domain to catch, no spelling error to notice, and no unfamiliar number to question. Security experts note the fraud’s success isn’t really about technical sophistication — it’s built almost entirely on urgency, authority, and psychological pressure. An employee sees a message from their actual boss, on a platform they use daily, asking for something confidential and time-sensitive. Compliance, in that moment, feels like the safe choice, not the risky one.

The pattern to recognize

Across the documented cases, the scam tends to follow a consistent shape:

  • Urgency — the request is framed as time-critical, often tied to a “confidential” deal, project, or emergency payment.
  • Authority — it comes from someone the target has no instinct to question: a CEO, MD, or department head.
  • Isolation from verification — the message often discourages or doesn’t allow time for the employee to check in through a separate channel before acting.
  • A financial ask — the end goal is almost always a wire transfer to an account the “boss” specifies.

What organizations are being told to do

SEBI’s core advisory to companies is straightforward: never approve a financial transaction based solely on a WhatsApp message, email, or social media message — regardless of who it appears to come from. Specific recommendations include:

  • Always verify independently. If a payment request comes in via WhatsApp, call the executive back using a known, previously saved phone number — not any number provided in the suspicious message itself.
  • Establish a callback or dual-approval policy for any urgent fund transfer request, especially ones framed as confidential or time-sensitive.
  • Be cautious with unexpected files. Never open unsolicited .zip attachments, even ones that appear to come from a colleague or executive — this is exactly the vector that leads to a hijacked WhatsApp account in the first place.
  • Watch for behavioral inconsistencies. A request that skips normal approval processes, discourages questions, or pressures immediate action is a red flag regardless of who appears to be sending it.

The bottom line

The uncomfortable truth about the Boss Scam is that the classic advice — “check for red flags in the message” — doesn’t fully apply anymore, because in the malware version of this attack, there often aren’t any. The account is real. The history is real. The only thing that’s fake is the instruction itself. That’s exactly why the fix isn’t smarter message-reading — it’s process. A financial transfer request should never be approved on the strength of a message alone, no matter how legitimate the sender appears, without a live, independent check-in through a channel the fraudster doesn’t control.

If your organization handles finance approvals over WhatsApp or similar messaging apps today, this is a good moment to introduce a callback verification step — before an urgent message from “the boss” turns out to be exactly the scam it’s designed to look nothing like.

Leave a Reply

Your email address will not be published. Required fields are marked *