On 7 August 2026, the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs cautioned corporates and finance professionals about a "Boss Scam" β self-propagating malware disguised as account statements and regulatory communications, spreading over WhatsApp, SMS and email, that takes over the accounts of senior executives and is then used to order high-value fraudulent transfers. Chartered Accountants, company directors, CFOs and corporate finance teams are the prime targets. For an NDA aspirant, cyber security is now a national-security subject, not merely a technical one.
The news in one frame
The essentials:
- The scam: malware posing as a "Statement of Account", "MCA" or "RBI" file, circulated on WhatsApp, SMS and email.
- The mechanism: it takes over the victim's WhatsApp account, then uses that trusted identity to instruct finance staff to transfer funds to mule accounts.
- The targets: Chartered Accountants, company directors, CFOs and corporate finance teams.
- Spread: identical cases reported from Delhi, Gujarat, Maharashtra and Rajasthan.
- Response: I4C alerted over 58,000 potential victims in 30 days through the SMS header 'I4CMHA-G'; shared threat signals with CERT-In, Microsoft and Indian anti-virus and threat-intelligence firms; and protected more than 10,000 Indians by geo-blocking command-and-control (C2) servers through the Sahyog Portal.
- I4C had issued an earlier advisory on 22 June 2026.
Why this attack works β social engineering
The concept at the heart of it, and the examinable idea:
- Social engineering is manipulating people rather than breaking systems. The attacker does not defeat the bank's encryption; he persuades a human being to move the money voluntarily.
- This scam stacks three psychological levers: 1. Authority β the instruction appears to come from the boss; 2. Trust in the channel β it arrives on WhatsApp, from a real, known account, not a suspicious email address; 3. Urgency β payment demands are framed as immediate, discouraging verification.
- The file names are the bait: "Statement of Account", "MCA", "RBI" are exactly the documents a finance professional expects to receive, so the attachment looks routine.
- Self-propagating means that once an account is compromised, the malware forwards itself to that person's contacts β so the sender is always someone the next victim already trusts.
The defence is procedural, not technical: verify any payment instruction through a second, independent channel β a phone call to a known number. That single habit defeats the entire attack, and it is the answer to give if asked.
This applied material is exactly what the NDA GAT science notes build.
The vocabulary you must know
A reliable set of definitional questions:
| Term | Meaning |
|---|---|
| Phishing | Fraudulent messages, usually email, luring victims into revealing credentials |
| Vishing / Smishing | The same by voice call / by SMS |
| Malware | Umbrella term β virus, worm, trojan, spyware, ransomware |
| Trojan | Malicious code disguised as a legitimate file β exactly this case |
| Worm | Malware that self-propagates without user action |
| Ransomware | Encrypts data and demands payment for the key |
| Mule account | A third party's bank account used to receive and move criminal proceeds |
| C2 server | The attacker's command-and-control machine that directs infected devices |
| Botnet | A network of compromised devices under common control |
| Zero-day | A vulnerability exploited before a patch exists |
| DDoS | Flooding a service with traffic to deny access to legitimate users |
A mule account holder is often a student or unemployed person paid a small commission β and is legally liable, a point worth making to any young audience.
India's cyber-security architecture
The institutional map, frequently mismatched in MCQs:
- I4C β Indian Cyber Crime Coordination Centre, under the MHA. The crime and policing arm. It runs the National Cyber Crime Reporting Portal (NCRP), the helpline 1930 for financial fraud, and the Citizen Financial Cyber Fraud Reporting and Management System, which can freeze a fraudulent transfer if reported quickly enough β hence the "golden hour".
- CERT-In β Indian Computer Emergency Response Team, under MeitY, the national nodal agency for cyber-security incident response, operating under the IT Act, 2000.
- NCIIPC β National Critical Information Infrastructure Protection Centre, under the NTRO, protecting critical sectors: power, banking, telecom, transport, defence and government.
- Defence Cyber Agency β the tri-service military cyber organisation.
- National Cyber Security Coordinator, in the National Security Council Secretariat.
- Law: the Information Technology Act, 2000 (amended 2008) β Section 66 covers computer-related offences, Section 66D cheating by personation, Section 43A data protection obligations; the DPDP Act, 2023 governs personal data; and the Bharatiya Nyaya Sanhita now carries the general fraud provisions.
- Sahyog Portal β the MHA platform for coordinating takedown and blocking requests with intermediaries.
These themes recur in the NDA daily current affairs.
The revision hook: "Boss Scam" β malware disguised as Statement of Account/MCA/RBI files on WhatsApp, SMS, email; hijacks a senior executive's WhatsApp, then orders staff to pay mule accounts; 58,000+ alerted in 30 days via SMS header I4CMHA-G, 10,000+ protected by geo-blocking C2 servers through the Sahyog Portal; I4C = MHA (crime), runs NCRP and helpline 1930; CERT-In = MeitY, national incident-response agency under the IT Act 2000; NCIIPC = under NTRO, protects critical information infrastructure; Defence Cyber Agency = tri-service; social engineering exploits authority, trust and urgency; trojan = disguised malware, worm = self-propagating, ransomware = encrypts for payment, mule account = used to launder proceeds, C2 = command-and-control; defence = verify on a second channel; report within the golden hour.
Why it matters
For the essay/interview and bigger picture:
- Cyber fraud is now a mass crime. It reaches more citizens than most conventional offences, and the losses are concentrated on those least able to bear them.
- The military dimension is real. The same techniques β social engineering, account takeover, self-propagating malware β are used in espionage and information operations against defence personnel. Officers are explicitly targeted; personal cyber hygiene is an operational duty, not a private matter.
- Awareness is the cheapest control. No firewall stops an authorised person voluntarily transferring money. Verification habits, not software, are the decisive defence β which is why an advisory of this kind is itself a security measure.
Exam relevance in one paragraph
For NDA GAT, retain: the Indian Cyber Crime Coordination Centre, or I4C, functions under the Ministry of Home Affairs as the crime and policing arm of India's cyber response, running the National Cyber Crime Reporting Portal and the financial-fraud helpline 1930, and on 7 August 2026 it warned of a "Boss Scam" in which self-propagating malware disguised as Statement of Account, MCA or RBI files spreads over WhatsApp, SMS and email, takes over the WhatsApp accounts of Chartered Accountants, directors and CFOs, and uses that trusted identity to instruct finance staff to transfer funds to mule accounts, with cases from Delhi, Gujarat, Maharashtra and Rajasthan, more than 58,000 potential victims alerted in thirty days and over 10,000 protected by geo-blocking command-and-control servers through the Sahyog Portal; the attack is social engineering, exploiting authority, trust in the channel and urgency, and the effective defence is verifying any payment instruction through a second independent channel; institutionally CERT-In under MeitY is the national nodal agency for cyber-security incident response under the Information Technology Act, 2000, while the National Critical Information Infrastructure Protection Centre under the NTRO protects critical sectors and the Defence Cyber Agency serves the armed forces, with the DPDP Act, 2023 governing personal data. For the essay, frame it as the weakest link is human, so the strongest control is a habit.
π― Practice MCQs
Q1. I4C functions under the Ministry of: (a) Home Affairs (b) Electronics & IT (c) Defence (d) Finance β (a) β the MHA.
Q2. CERT-In functions under the Ministry of: (a) Electronics & IT (b) Home Affairs (c) Defence (d) Communications β (a) β MeitY.
Q3. India's helpline for reporting financial cyber fraud is: (a) 1930 (b) 100 (c) 1098 (d) 112 β (a) β 1930.
Q4. CERT-In derives its mandate from the: (a) IT Act, 2000 (b) DPDP Act, 2023 (c) Telegraph Act, 1885 (d) BNS β (a) β the Information Technology Act, 2000.
Q5. NCIIPC protects: (a) critical information infrastructure (b) household devices (c) social media (d) postal services β (a) β power, banking, telecom, transport, defence.
Q6. Manipulating people rather than systems is called: (a) social engineering (b) reverse engineering (c) hacking hardware (d) encryption β (a) β social engineering.
Q7. Malware disguised as a legitimate file is a: (a) trojan (b) worm (c) firewall (d) patch β (a) β a trojan.
Q8. Malware that spreads by itself without user action is a: (a) worm (b) trojan (c) cookie (d) macro β (a) β a worm; "self-propagating" is the clue.
Q9. A "mule account" is used to: (a) receive and move criminal proceeds (b) pay taxes (c) hold savings (d) trade shares β (a) β laundering the fraud proceeds.
Q10. A "C2 server" refers to: (a) command-and-control (b) cloud computing (c) cyber certification (d) code compiler β (a) β the attacker's control machine.
Q11. Fraud attempted through voice calls is: (a) vishing (b) phishing (c) smishing (d) sniffing β (a) β vishing (SMS is smishing).
Q12. Ransomware typically: (a) encrypts data and demands payment (b) deletes hardware (c) speeds up a PC (d) blocks electricity β (a) β encryption for extortion.
Q13. A "zero-day" vulnerability is one that: (a) is exploited before a patch exists (b) lasts one day (c) affects no one (d) is already fixed β (a) β unknown to the vendor.
Q14. The tri-service military cyber organisation is the: (a) Defence Cyber Agency (b) CERT-In (c) NCIIPC (d) I4C β (a) β the Defence Cyber Agency.
Q15. The most effective defence against this scam is: (a) verifying the instruction on a second channel (b) a stronger password (c) a faster computer (d) deleting WhatsApp β (a) β independent verification.
π How this gets asked (PYQ pattern)
Cyber security is a reliable NDA sci-tech set. The reliable framings are body-to-ministry matching (I4C-MHA, CERT-In-MeitY, NCIIPC-NTRO), the 1930 helpline, malware type definitions (trojan, worm, ransomware), and phishing vs vishing vs smishing. A common trap places CERT-In under the Home Ministry or calls a self-propagating program a trojan (it is a worm). The fresh 2026 hook is the I4C Boss Scam advisory β ideal for "which agency / which term / which ministry" items. We reference the pattern, not any exact past question.
Preparing for NDA? Cyber security is now core GAT material and a serious SSB discussion topic β officers are themselves targets of social engineering. Follow our daily NDA current affairs and train with serving-officer faculty in the upcoming Cavalier courses in Delhi.
βοΈ Written by Aditya Tiwari β Technology, security & current-affairs faculty at The Cavalier. Reviewed by the Cavalier Faculty Desk. The Cavalier, founded by ex-Army officers, has trained NDA/CDS/SSB aspirants since 2001 (Facebook Β· YouTube).
Source: PIB / Ministry of Home Affairs (I4C), 7 August 2026. Facts cross-verified with independent sources.