In three months, 68 fall victim to ‘boss scam’

Representational Photo

Bhubaneswar: Cybercriminals are repeatedly changing their modus operandi, posing a fresh challenge to police. Whenever police alert people about one type of fraud, the criminals adopt a new tactic to dupe them.

The latest concern in cybercrime is the so-called ‘Boss Scam’, in which cybercriminals target chartered accountants, company directors, big businessmen, chief financial officers and CEOs, allegedly siphoning off crores of rupees.

As many as 68 people have reportedly fallen victim to cyber fraud of this nature in the past three months.

The fraudsters send files such as ‘Statement of Account. zip’, ‘RBI.zip’ and ‘SBI.zip’ through mobile messages, WhatsApp and email, making them appear to have been sent by the Reserve Bank of India, Ministry of Corporate Affairs or Income Tax department.

Opening such a ZIP file can compromise the victim’s WhatsApp account, as cyber criminals hide malware inside the files.

Once the file is opened, the malware becomes active on the device, allowing the criminals to take control of the WhatsApp account.

The hacked account is then used to send similar files to colleagues, customers and WhatsApp groups, allowing the fraud to spread further.

In the first step, cyber criminals take control of the WhatsApp account of a senior official, businessman or person handling fi nancial trans actions.

They then use the account to send messages to company employees, asking them to make urgent payments.

At times, employees are asked to transfer money for an emergency requirement, while in other cases they are instructed to make an immediate payment to a specific bank account.

Since the messages appear to come from the WhatsApp account of the actual head of the company, employees often do not suspect any wrongdoing and transfer the money.

In a case of this type of fraud, cyber police arrested three persons from Kolkata two days ago. The accused had sent a ZIP file to an employee at a company.

After hacking his WhatsApp account, they used it to send messages to the office group asking employees to transfer money.

The files are given names that are likely to prompt recipients to open them immediately. They contain malicious executable files along with other supporting files.

Once opened, the malware becomes active and poses a threat to the security of the account and device.

Cyber expert Nousad Alam advised people not to download or open any ZIP file received from an unknown source.

He said suspicious files appearing to come from banks, government departments or companies should be verified before being opened

Orissa POST – Odisha’s No.1 English Daily
Exit mobile version