Back Darkreading Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition (M&A) deals.
It's one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.
"Scams are becoming so convincing that even the most trained eye can have trouble spotting them," says Gen security evangelist Luis Corrons, who co-authored a report on the campaign with Martin Chlumecký, senior principal threat analysis engineer at Gen.
In this case, luckily, the company was saved by an attentive employee and some cracks in the attackers' narrative. "The attackers' methodology was quite sophisticated, but their individual scenario was imperfect," Corrons says. "With a more coherent story, the same playbook could have been much more dangerous."
Related: AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The threat actors behind the campaign, dubbed "Phantom Deal," did their homework. They identified a member of Gen's legal team, referred to as "David," who might be expected to have a role in whatever sort of corporate dealmaking was going on at the company. The first phishing message, via WhatsApp , was friendly and nondescript. An attacker impersonated one of the company's executives. Their phone number correctly utilized the executive's country's area code.
The executive had news for the employee, on the down low. They were facilitating a major corporate acquisition. The details were a little vague. It involved Gen's subsidiaries and a big, fat check.
"They never gave David a completely coherent explanation of exactly who was acquiring whom," Correns recalls. "What they did was build around real corporate history. NortonLifeLock acquired Avast in 2022, and the fraudulent payment instructions asked Avast Software to make a payment on behalf of NortonLifeLock Ireland Limited, supposedly connected to a confidential acquisition and reimbursable when the deal was announced. That was enough to create a plausible mergers and acquisitions (M&A) context, but if you looked closely, the story did not really add up."
The story structure may have fallen short of The Odyssey , but every other operational detail was spot on. A second threat actor impersonated a middleman at PricewaterhouseCoopers (PwC). They had a non-disclosure agreement (NDA) written up, with PwC branding. The NDA cleverly swore the employee to secrecy — keeping other employees out of the ruse — and instructed them to limit all communications to WhatsApp and personal email addresses — keeping their suspicious messages away from the prying eyes of corporate monitoring systems. The secret deal narrative gave context to what otherwise would have been totally suspicious asks.
Related: Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
Then came the big ask: An oddly specific €626,735.45 Euro transaction needed to be sent to a company in Hong Kong to facilitate the deal.
The fiction only fell apart because the employee and the attackers got on the phone , and the employee recognized that the impersonated executive's voice was wrong. At that point, the attackers became the attack-ees. Gen drafted a fake transaction confirmation email, keeping the bad guys thinking they were on the cusp of success. The email contained a link with a token, which tracked the attacker's actions and connections.
With metadata from the fake NDA, researchers were able to identify four other targets of the same campaign. The targets were all senior employees, belonging to companies of all different sorts: private equity, industrial finance, sales, mining, and energy. For the most part, each attack was entirely customized to its target, even down to the professional services firm — PwC, KPMG, Ogier — used to facilitate their "phantom deal."
Related: Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Companies reveal a huge amount of information themselves on the public Internet. What made Phantom Deal convincing was all of the detail the social engineers were able to gather their target, using simple Web searches. Still, Corrons argues, the answer to fighting them isn't to take that information off the Net.
"The attackers used names, photographs, job roles and acquisition history, most of which is legitimately public and, in many cases, needs to be public. Security through obscurity would not solve this problem," he says. "I would not want companies relying on the attacker having incomplete information. Assume criminals can learn a great deal your organization. The defense has to be that even somebody who's done excellent reconnaissance still cannot talk an employee into bypassing verification and payment controls."
It helps, too, if employees know better than to try bypassing those controls in the first place. The hero of Gen's story, "David," undressed an otherwise compelling attack through basic attention to detail. "First, he verified the person rather than trusting the identity presented on the screen. Second, he understood what a legitimate transaction should look like," Correns notes.
The lesson for everyone else, he says, is: "Don't just ask whether the person looks legitimate, ask whether the process they are asking you to follow is legitimate. For most employees, once they suspect something, the correct step is to report it, not to continue engaging with the scammer. Even if you report it and it’s a legitimate transaction, your company will appreciate that you're being safe."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Building an Effective Red Team: Beyond Penetration Testing
Building an Effective Red Team: Beyond Penetration Testing
How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach
How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach
Cloud Incident Response: Forensics in Distributed Environments
Cloud Incident Response: Forensics in Distributed Environments
Beyond the Login: Key Considerations for Evaluating Identity Security
Beyond the Login: Key Considerations for Evaluating Identity Security
SASE Pivot and Trends 2026: A Gartner Keynote
SASE Pivot and Trends 2026: A Gartner Keynote
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days
CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks
Deja Vu: Salesforce Customers Hacked Again, Via Gainsight
Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
