New Delhi, August 7, 2026 (Yes Punjab News)
More than 10,000 Indians have been protected from a WhatsApp account takeover campaign following coordinated action by the Indian Cyber Crime Coordination Centre (I4C), the Ministry of Home Affairs (MHA) said on Friday.
The MHA said that I4C’s interventions, including geo-blocking of command-and-control (C2) servers through the Sahyog Portal, helped prevent further spread of the malware campaign targeting WhatsApp users.
In a statement, the ministry said I4C had detected a significant increase in complaints registered on the National Cyber Crime Reporting Portal (NCRP) related to WhatsApp account takeovers through malicious files disguised as account statements and communications allegedly issued by regulatory authorities.
“Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal,” the MHA said.
According to the ministry, similar incidents involving the same modus operandi have been reported from multiple states, including Delhi, Gujarat, Maharashtra and Rajasthan. I4C had earlier issued an advisory on June 22, warning citizens about the growing threat of cybercriminals impersonating regulatory and government authorities to gain access to WhatsApp accounts.
The MHA said victims typically receive compressed files through WhatsApp, SMS or email carrying names such as “Statement of Account.zip” or “RBI.zip”, designed to appear like routine financial documents or urgent notices.
These files often contain malicious software that installs a Trojan when extracted and opened on a Windows computer. The malware can compromise the device and hijack an active WhatsApp Web session linked to the victim’s account.
“In many cases, emails are also sent impersonating the Income Tax Department,” the ministry said.
Once a WhatsApp account is compromised, cybercriminals use it to automatically circulate the same malicious file to the victim’s contacts and groups. The messages often instruct recipients to forward the file to their company’s finance manager for verification and open it on a computer, allowing the malware to spread further, including into corporate networks.
The government has advised citizens to avoid opening suspicious attachments, especially files received from unknown sources, and to verify messages claiming to be from regulatory or government agencies before taking any action.



































































































