WhatsApp Payment Scams Targeting Accountants
- Cybercriminals have deployed a sophisticated WhatsApp impersonation fraud targeting high-level corporate executives and financial officers in Hyderabad.
- According to Hyderabad Police Commissioner VC Sajjanar, the attack begins with the delivery of malicious phishing links sent to official corporate email addresses.
- Once the attackers gain control of a corporate system, they exploit active WhatsApp Web sessions.
Cybercriminals have deployed a sophisticated WhatsApp impersonation fraud targeting high-level corporate executives and financial officers in Hyderabad. The scheme specifically targets CEOs, CFOs, business heads, and accountants of large corporations to facilitate the theft of significant sums of money.
According to Hyderabad Police Commissioner VC Sajjanar, the attack begins with the delivery of malicious phishing links sent to official corporate email addresses. These links are designed to infiltrate computer systems with malware, granting attackers full remote access to the infected machines.
Technical Execution of the Fraud
Once the attackers gain control of a corporate system, they exploit active WhatsApp Web sessions. Because WhatsApp Web mirrors the account of the user on the connected device, the fraudsters can send messages that appear to originate from the actual account of a top executive.
The attackers use social engineering tactics to manipulate corporate staff. They typically pose as a CEO or CFO and claim to be in an urgent meeting, stating they are unable to take phone calls. Under this guise of urgency, they instruct accountants to immediately transfer crores of rupees to fraudulent bank accounts.
Because the messages are sent from the legitimate WhatsApp account of the executive, accountants often believe the requests are genuine and process the payments without further verification.
Broader Context of WhatsApp Impersonation
This corporate-targeted attack is a specialized version of broader impersonation scams. General impersonation fraud often involves attackers pretending to be friends, colleagues, or family members—sometimes referred to as a Mom and Dad scam
—where fraudsters claim to have a new phone number or use stolen profile pictures to create urgent scenarios requiring financial aid.
The Hyderabad cases represent a shift toward high-value targets by combining traditional social engineering with technical system infiltration via malware and session hijacking.
Prevention and Mitigation Strategies
Hyderabad Police have warned that companies must remain highly vigilant and avoid blind trust in financial requests received via WhatsApp, regardless of whether the request appears to come from a superior.
To defend against these attacks, organizations are encouraged to implement the following security measures:
- Verifying all payment requests through a direct phone call to the requester.
- Providing specialized training for finance and accounting teams to recognize social engineering and phishing attempts.
- Avoiding the processing of financial transactions based solely on WhatsApp instructions.
The use of phishing links via official email remains the primary entry point for these attackers, highlighting the need for robust email security and endpoint protection to prevent the initial installation of remote-access malware.
