Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Cyber frauds reinvent whale phishing attacks, make it more invasive & deadly

Cyber frauds reinvent whale phishing attacks, make it more invasive & deadly

Cybercriminals are evolving traditional whale phishing attacks by infiltrating computers of senior finance executives, tampering with contact details, and sending fraudulent money transfer requests from compromised devices. In Pune and Pimpri Chinchwad, police have registered multiple cases involving hacked WhatsApp Web sessions, allowing fraudsters to appear genuine and persuade victims to transfer large sums of money.

One incident involved an accountant transferring Rs 70 lakh to mule accounts after being duped by a fraudulent message posing as the company's CEO. Another case saw an automobile dealer lose Rs 2.2 crore after their accounts executive's device was hacked, and the fraudsters posed as the CEO. Cyber investigators stated that the attacks usually commence when a victim opens a malicious file or link, granting cybercriminals access to active WhatsApp Web sessions.

They can then view existing conversations, identify key financial decision-makers, and manipulate contact information to make fraudulent messages seem legitimate. Once inside the compromised device, fraudsters alter the victim's contact list, saving the genuine CEO's number under a different name and blocking it. They then replace it with a fraudulent number carrying the CEO's name and display picture, causing messages to appear as if they're coming from a trusted contact.

The sophistication of these attacks lies in their ability to exploit trust built over months or years of legitimate communication. Fraudsters replicate the language, tone, and working patterns of senior executives by studying previous exchanges, increasing the likelihood of victims falling for the scam. To mitigate such risks, police advise companies to verify payment instructions through independent phone calls and regularly review active WhatsApp Web sessions.

Enabling multi-factor authentication, restricting unverified software installations, and conducting periodic cyber-security audits are also recommended. Finance teams should adopt dual-approval mechanisms for high-value transactions and undergo regular awareness training to recognize phishing signs and account compromises.

Written by urgent.news from The Indian Express's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at indianexpress.com →

More in Tech

A Beginners Guide To Closures

Introduction If you've been writing JavaScript for some time now, you've probably used a closure without realizing it, maybe in a setTimeout, an event listener, or a function that returns another…

🚀 Como comunicar .NET 10 com Pydantic usando Logfire

Uma implementação simples de observabilidade com OpenTelemetry Quando pensamos no ecossistema Pydantic , normalmente associamos a tecnologia ao Python, validação de dados e aplicações de Inteligência…

  • .NET 10 applications communicate with Pydantic ecosystem via Logfire
  • OpenTelemetry protocol transports telemetry data between platforms
  • Install OpenTelemetry packages and configure Logfire endpoint in .NET 10

More from Thursday 20 August →