← Back to Blog

The ZIP File From the Manager: How One WhatsApp Attachment Can Lead to Fake Payment Instructions

A ZIP file that looks like an RBI notice, account statement, or manager’s document can compromise a business device and hijack WhatsApp Web. Learn how the “boss scam” works, the warning signs to spot, and the steps Indian finance teams must take before any payment.

A WhatsApp message from a manager can look normal. A file named Statement of Account.zip can look routine. But opening the wrong ZIP file on a work computer can give criminals a path into your business communications—and eventually your bank account.


This fraud pattern is often called the WhatsApp Boss Scam or CEO impersonation scam. It begins with a malicious ZIP attachment disguised as an account statement, an RBI or MCA notice, an audit report, a compliance document, or a security update. If someone extracts and runs the hidden malicious file on a Windows computer, attackers may take over an active WhatsApp Web session and send payment instructions from what appears to be the real manager’s account.pib


The most important protection is simple:

Never open unexpected ZIP files. Never release a payment based only on WhatsApp, email, Teams, or another chat message.


The Scam in 60 Seconds


Step 1: The fake file arrives


What criminals do:

They send a ZIP attachment over WhatsApp, email, or SMS. It may appear to be an RBI notice, account statement, GST document, invoice, audit report, or compliance file.

What you may see:

textStatement of Account.zip
RBI Notice.zip
MCA Compliance.zip
GST Notice.zip
Pending Invoice.zip

What to do:

Do not download, extract, or open an unexpected ZIP file. Verify the sender through a known phone number or official email address.


Step 2: Malware is hidden inside

What criminals do:

The ZIP folder contains a harmful file, often an .exe, .dll, .bat, .js, or .vbs file. The filename or icon may be made to look like a PDF, Excel sheet, or official document.

What you may see:

textStatement_of_Account.pdf.exe
RBI_Update.exe
Invoice_Review.dll
MCA_Notice.bat

What to do:

A real business document should normally be a PDF, Excel, Word, or verified portal download—not an executable program. Never run unknown files on a work laptop.


Step 3: WhatsApp Web can be compromised

What criminals do:

If the malicious file runs on a computer with WhatsApp Web logged in, the attackers may attempt to misuse that active WhatsApp session.

What you may see:

The manager’s WhatsApp account still looks normal. Their profile photo, name, previous messages, and chat style may all appear genuine.

What to do:

Open WhatsApp and review:

textSettings → Linked Devices

Log out of any browser, computer, or session you do not recognise.


Step 4: A fake payment instruction arrives

What criminals do:

The attacker sends an urgent payment request from the compromised WhatsApp account of a manager, director, CEO, or finance head.

What you may see:

“Please transfer the payment immediately.”
“This is confidential. Do not discuss it with anyone.”
“I am in a meeting, so do not call.”
“Use these new account details.”
“Send the payment confirmation once completed.”

What to do:

Do not send money, account balances, OTPs, payment screenshots, or bank information based only on a WhatsApp message.


Step 5: The money is sent to a new account

What criminals do:

The attacker provides a new beneficiary account, UPI ID, or changed vendor bank details. The money may then be moved rapidly through multiple accounts.

What you may see:

textNew beneficiary: ABC Enterprises
Account number: [new account]
IFSC: [bank code]
Reason: Urgent vendor settlement

What to do:

Call the manager using their official, saved phone number. Then verify the vendor through an existing contact—not the contact details included in the WhatsApp message.


Step 6: The fraud is discovered too late

What criminals do:

After receiving the money, they may delete chats, stop responding, or move funds to other accounts.

What you may see:

A payment that cannot be matched with a legitimate invoice, purchase order, contract, or vendor confirmation.

What to do immediately:

  • Contact your bank and request a transaction hold or recall.
  • Call India’s Cyber Crime Helpline: 1930.
  • Report the incident at cybercrime.gov.in.
  • Log out of WhatsApp Web from all linked devices.
  • Inform your IT team, finance head, and company leadership.
  • Preserve screenshots, ZIP files, chats, payment details, and device logs.


Indian government guidance has warned that victims may receive compressed .zip files via WhatsApp, SMS, or email with names such as Statement of Account.zip, RBI.zip, or MCA.zip. These files can include malware that compromises a device and is then used for high-value fraud.pib



How the Attack Happens

9:12 AM — The “urgent” file arrives

An executive or employee receives a WhatsApp message that appears to be from a bank, regulator, vendor, auditor, or senior manager.

The message may say:

“Please review the attached RBI compliance document urgently.”

Or:

“Your account statement is attached. Confirm the details today.”

The attached file may be called:

textStatement of Account.zip
RBI.zip
MCA.zip
GST Notice.zip
Pending Invoice.zip
Security Update.zip
Audit Report.zip

The goal is to create urgency before the employee has time to verify the sender.


9:14 AM — The ZIP file is opened

The employee downloads the ZIP file to a Windows laptop or office computer. Inside, there may be an executable file such as .exe or a related library file such as .dll.

The file might use a misleading name or icon to resemble a PDF, Excel file, or document.

Opening a ZIP file alone is not necessarily enough to compromise a device. The main danger is extracting and executing a malicious program hidden inside it. That is why unexpected .zip, .exe, and .dll files should never be opened unless the sender and business purpose have been independently verified.pib

+1


9:16 AM — WhatsApp Web becomes the target

Many executives use WhatsApp Web on office computers. If malware runs on that device, attackers may attempt to hijack or misuse the active WhatsApp Web session.

Now the criminal may be able to read conversations, study the company’s communication style, identify finance employees, and send messages that appear to come from the actual executive.

The manager’s display photo, name, chat history, and normal tone make the messages look authentic.


10:02 AM — A finance employee receives the payment request

The attacker sends a message from the compromised WhatsApp account:

“Please make this payment urgently. It is for a confidential vendor settlement. Do not delay.”

The fraudster may include:

  • A beneficiary name
  • A bank account number
  • An IFSC code
  • A UPI ID
  • A payment amount
  • A fake invoice
  • A promise that paperwork will follow
  • A request to keep the transaction confidential

The finance employee sees the message from their real manager’s WhatsApp account. That trust is the attacker’s advantage.


10:07 AM — Pressure replaces verification

The scammer may use pressure tactics:

  • “I am in a meeting. Do not call.”
  • “This is time-sensitive.”
  • “The director already approved it.”
  • “Use the new account details.”
  • “Do not involve anyone else.”
  • “I need the payment confirmation now.”
  • “We will reconcile documents later.”

This is the critical moment. A single independent callback can stop the fraud.


10:15 AM — The transfer is made

If the team follows the message without verification, funds can be sent to a mule account. Criminals often try to move or withdraw funds quickly, which makes rapid reporting essential.

Indian authorities advise businesses to independently confirm urgent fund-transfer or account-change requests through a direct voice call or in-person confirmation before acting.


Why This Scam Is So Dangerous

This scam combines malware, impersonation, and financial social engineering.


It comes from a trusted-looking person

The request may come from the actual WhatsApp account of a director, CEO, manager, or finance head after their session is compromised. A known profile photo and familiar account are not enough proof for a payment request.


It looks like routine business work

The attacker may disguise the initial ZIP file as a statement, compliance document, audit file, payment reconciliation, tax notice, or vendor document.


It targets the people who can move money

The final message usually reaches finance, accounts, procurement, treasury, or executive-assistant teams—the people who can initiate or approve payments.


It creates fear, urgency, and secrecy

Fraudsters want employees to act before they question the request. “Urgent,” “confidential,” and “do not call” are not business approvals. They are warning signs.


It bypasses traditional security habits

Some teams know not to click phishing links, but they may not treat a WhatsApp attachment or a message from their manager as suspicious. This attack exploits that trust.


10 Warning Signs of a Malicious ZIP File Scam

Stop and verify if you notice even one of the following:

  1. An unexpected ZIP file from an unknown, unverified, or unusual number.
  2. A message claiming to be from RBI, MCA, GST, a bank, or another regulator through WhatsApp.
  3. A file named RBI.zip, Statement of Account.zip, MCA.zip, or a similarly urgent-sounding attachment.
  4. A ZIP file that contains .exe, .dll, .bat, .js, .vbs, or other executable files.
  5. A message that demands “immediate” action.
  6. A senior executive requests a high-value transfer only through WhatsApp.
  7. The payment is going to a new, unusual, or unverified beneficiary.
  8. The sender asks you not to call, verify, or involve other approvers.
  9. The request bypasses a normal purchase order, invoice, vendor-verification, or approval process.
  10. You see a WhatsApp Web device you do not recognise under WhatsApp Settings → Linked Devices.


The One Rule That Stops Most Boss Scams

No employee should approve, initiate, or release an unusual payment solely because they receive an instruction on WhatsApp.

A WhatsApp message is communication—not payment authorisation.

For every high-value payment, new beneficiary, bank-detail change, or unusual request, complete an out-of-band verification. This means verify using a channel that the suspicious message did not control.

For example:

  • Call the manager using their known company phone number.
  • Speak in person to the director.
  • Use the official corporate email and normal approval workflow.
  • Check the payment request against a valid purchase order and invoice.
  • Get a second authorised approver to confirm the transaction.

Do not call the number sent inside the suspicious chat. Use a number saved in your official company directory.


What Finance Teams Should Do Before Paying

Use this five-step process for every unusual payment request.


Step 1: Pause

Do not send payment confirmation, bank balance information, OTPs, or beneficiary details in the chat.

A message can be urgent. Your payment process should still be controlled.


Step 2: Verify the source

Ask:

  • Did this manager really send the request?
  • Was their WhatsApp account compromised?
  • Is the message consistent with normal business practice?
  • Is the request supported by documents and approvals?

Step 3: Call independently

Call the manager or director on their official, previously saved phone number.

Confirm all five details:

text1. Payment amount
2. Beneficiary name
3. Bank account number / UPI ID
4. Business reason
5. Required payment deadline

Step 4: Verify the beneficiary

For new or updated bank details:

  • Confirm with the vendor using a known contact number.
  • Check legal business name and invoice details.
  • Compare the bank account holder with the vendor name.
  • Do not use contact details sent in the suspicious message.
  • Escalate any mismatch to a manager or finance controller.

Step 5: Use two-person approval

For large payments, require at least two authorised people to review and approve the transaction.

A good workflow is:

textFinance executive initiates → Finance manager verifies → Authorised signatory approves → Bank transfer is released


How to Protect Your WhatsApp Web Session

Review linked devices regularly

On WhatsApp:

textSettings → Linked Devices

Review every device listed. If you see a browser, computer, location, or session you do not recognise, log it out immediately.

Government guidance specifically recomends regularly reviewing linked devices and logging out of inactive WhatsApp Web sessions.


Log out when you are not using WhatsApp Web

Do not leave WhatsApp Web signed in on shared, public, or unmanaged computers.

At the end of the workday, log out from the browser or remove the linked device from WhatsApp.


Enable two-step verification

Turn on WhatsApp two-step verification and keep the associated recovery email secure. This adds an additional protection layer to your WhatsApp account.


Keep devices updated

Install operating-system updates, browser updates, and reputable endpoint security or antivirus updates. Malware often succeeds when devices are outdated or users are allowed to run unverified software.


Restrict executable files on company devices

IT teams should consider policies that prevent unauthorised .exe and .dll files from running from downloads, temporary folders, user-profile directories, and other common locations.

Government guidance recommends enforcing software restrictions to block unknown executables and DLL files, alongside up-to-date anti-malware protection on Windows endpoints.


What To Do If Someone Opens a Suspicious ZIP File

Act quickly. Do not wait to see whether something “looks wrong.”


Immediate response checklist

  1. Disconnect the affected computer from Wi-Fi or the network if possible.
  2. Do not open any additional files or click any links.
  3. Log out of all WhatsApp Web and Linked Devices sessions immediately.
  4. Change passwords for important business accounts from a separate, clean device.
  5. Inform your IT or security team.
  6. Run a full endpoint-security or antivirus scan.
  7. Review recent WhatsApp messages for unauthorised payment instructions.
  8. Alert employees, customers, vendors, and finance contacts not to trust recent unusual messages from the affected account.
  9. Contact your bank immediately if payment details were shared or a transfer was initiated.
  10. Report suspected cyber fraud immediately by calling 1930 and filing a report at the National Cyber Crime Reporting Portal: cybercrime.gov.in.

The Government of India advises compromised users to log out from linked devices, alert contacts, scan the computer using updated antivirus software, and report cyber fraud to 1930 or the National Cyber Crime Reporting Portal.


The 30-Second Staff Quiz

Use this in your next finance or operations meeting.


Scenario

Your manager sends you a WhatsApp message:

“Please open MCA Compliance.zip. After that, transfer ₹4.5 lakh to this new account. This is urgent and confidential. I’m in a meeting, so please don’t call.”

What should you do?

  • Open the ZIP file because it came from your manager.
  • Transfer the money because the request is confidential.
  • Reply asking for an invoice and send the payment.
  • Do not open the file, call the manager on their official number, and follow the normal approval process.

Correct answer: Do not open the file. Independently call the manager using a known official number, verify the request, verify the beneficiary, and follow dual approval before any payment.


How ScamShield AI Helps

ScamShield AI helps Indian businesses assess suspicious messages, payment requests, attachments, links, screenshots, and fraud signals before employees take action.

For this type of attack, teams can use ScamShield AI to review:

  • WhatsApp payment instructions that look urgent or unusual
  • Suspicious ZIP-file names and attachment signals
  • Impersonation and social-engineering language
  • New beneficiary or bank-account details
  • Fraudulent invoices and payment screenshots
  • Links, QR codes, and suspicious documents
  • India-specific fraud patterns affecting finance teams and SMEs

ScamShield AI supports a stronger process—but no tool should replace independent payment verification. The best defence remains:

Pause. Verify through a trusted channel. Then pay.


Frequently Asked Questions

Can a ZIP file hack WhatsApp?

A ZIP file is a compressed folder, and it is not automatically harmful by itself. However, a ZIP file can contain malicious executable files. If an employee extracts and runs that malware on a computer, it may compromise the device and potentially enable misuse of an active WhatsApp Web session.pib

+1


Does RBI send ZIP files through WhatsApp?

Government guidance warns that fraudsters may use names such as RBI.zip to impersonate regulators. RBI and other regulators should not be treated as legitimate merely because a WhatsApp message uses their name. Independently verify any notice through official websites and known contact channels.pib

+1


What is a WhatsApp boss scam?

A WhatsApp boss scam is a fraud in which attackers impersonate or compromise the account of a CEO, director, manager, or senior executive and send urgent messages instructing employees to transfer money or change payment details.economictimes

+1


How can I tell if WhatsApp Web is compromised?

Open WhatsApp and go to Settings → Linked Devices. Look for unfamiliar browsers, computers, or active sessions. Log out of any session you do not recognise and notify your IT or security team.


Can I trust a payment instruction from my manager’s WhatsApp?

Not by itself. Even a message from a real manager’s account may be sent by a fraudster if the account or linked device has been compromised. Independently verify every unusual or high-value payment through a direct call or approved business workflow.


What should I do after a fraudulent bank transfer?

Contact your bank immediately, call the National Cyber Crime Helpline at 1930, file a report at cybercrime.gov.in, preserve all evidence, notify your security team, and warn relevant contacts. Rapid reporting can improve the chance of freezing or recovering funds.


Final Takeaway

The most dangerous file in your inbox may not look dangerous at all. It can look like an account statement, a tax notice, a compliance document, or a file from your manager.

The ZIP file is only the first step. The real target is trust: trust in WhatsApp, trust in a familiar executive, and trust in an urgent payment request.

Protect your business with three habits:

  1. Never open unexpected ZIP or executable files.
  2. Review WhatsApp Linked Devices regularly and log out of inactive sessions.
  3. Verify every unusual payment through an independent call and a second approval.

When a message asks for money, urgency is never a reason to skip verification.