WhatsApp account takeover scam: I4C protects more than 10,000 Indians

07 August,2026 03:22 PM IST |  New Delhi  |  mid-day online correspondent

Indian Cyber Crime Coordination Centre has protected more than 10,000 Indians from a WhatsApp account takeover campaign involving malicious ZIP files disguised as account statements and regulatory notices. I4C has blocked malware and command-and-control servers through the Sahyog Portal

Representational image. File pic


Your browser doesn’t support HTML5 audio

The Indian Cyber Crime Coordination Centre (I4C) has protected more than 10,000 Indians from a WhatsApp account takeover campaign. The centre on Friday said that coordinated action was taken by the Indian Cyber Crime Coordination Centre (I4C), including geo-blocking of command-and-control (C2) servers through the Sahyog Portal.

While issuing an official advisory, the Ministry of Home Affairs (MHA) said that I4C has observed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) regarding the takeover of WhatsApp accounts through malicious files disguised as account statements and communications purportedly issued by regulatory authorities.

The Ministry said, "Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal," as per IANS.

Victims received compressed .zip files

According to the MHA, incidents following an identical modus operandi have been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan.

I4C had earlier issued an advisory on June 22 warning citizens about the emerging threat involving regulatory and executive impersonation for WhatsApp account takeovers.

They further explained, "In the reported incidents, victims receive a compressed (.zip) file over WhatsApp, SMS or e-mail bearing names such as Statement of Account.zip (often prefixed with a date, for example 0714 Statement of Account.zip or RBI.zip, MCA.zip."

The file contains malicious components that can hijack your data

These messages are crafted to resemble routine account statements or urgent notices from regulators, prompting recipients to open the files immediately.

The Ministry further noted, "When the file is extracted and opened on a Windows desktop or laptop, a Trojan is installed which compromises the device and hijacks the victim's active WhatsApp Web session. In many cases emails are also sent impersonating the Income Tax Department," as per IANS.

"The compromised WhatsApp account is thereafter misused to automatically circulate the same malicious file to all the contacts and groups of the victim, typically with a request to forward the file to the recipient's "company finance manager for verification" and to open it on a computer, thereby extending the chain of infection deeper into corporate networks," they further added.

(With inputs from IANS)

"Exciting news! Mid-day is now on WhatsApp Channels Subscribe today by clicking the link and stay updated with the latest news!" Click here!
India news WhatsApp Technology Cybersecurity Cyber crime
Related Stories