Back to Hyderabad

Telangana Cyber Bureau Warns of Boss Scam After 300 Complaints Reported

Telangana Cyber Bureau Warns of Boss Scam After 300 Complaints Reported

The Telangana Cyber Security Bureau (TGCSB) has issued a public advisory warning government departments, businesses, and organisations across Telangana and the rest of the country about a rapid rise in "Boss Scam" or CEO impersonation fraud. The warning comes after more than 300 complaints related to this cyber fraud were reported nationwide within a span of nearly 20 days.

According to the advisory, cybercriminals are targeting senior executives, government officials, business owners, and organisational leaders. The fraudsters send emails and WhatsApp messages disguised as urgent regulatory, compliance, or official communications to compromise active WhatsApp Web sessions.

Investigators revealed that the scam typically begins with cybercriminals sending malicious ZIP or RAR files disguised as official notices or urgent communications. Once an unsuspecting victim opens the attachment, malware is installed on their device. This gives the attackers unauthorised access to the victim's active WhatsApp Web sessions and other sensitive information.

The compromised accounts are subsequently used to impersonate senior officials or company executives. The fraudsters then send direct instructions to subordinate staff, finance teams, or other employees, pressuring them to make urgent financial transfers or disclose confidential data.

The TGCSB stated that the scam relies heavily on exploiting trust, authority, and urgency. This pressure often convinces employees to bypass established approval procedures under the belief that the instructions came directly from a senior official.

Officials have advised organisations to remain alert to warning signs, such as unexpected ZIP or RAR attachments, messages marked as urgent compliance requests, and instructions received solely through email or WhatsApp. Requests for confidential financial transactions and attempts to circumvent standard approval processes should also raise red flags.

The bureau urged businesses and government departments to independently verify all financial instructions through direct phone calls or official communication channels. It also recommended enabling multi-factor authentication, regularly reviewing active WhatsApp Web sessions, avoiding suspicious attachments, and conducting regular cyber security awareness programmes for employees.

The TGCSB requested victims or those who encounter such fraud attempts to report them immediately through the National Cybercrime Helpline on 1930 or the National Cybercrime Reporting Portal.

Share