ThreatCluster

Phantom Deal Scam Targets Corporations with Fake NDAs

First seen 3 Sep 2026, 21:30 UTC GbhackersCybersecuritynews 65

Article Content

Browse articles
ThreatCluster

Cybercriminals executed a scam called Phantom Deal, impersonating executives and consulting firms to pressure a legal employee into transferring €626,735.45 to a Hong Kong entity. The attack utilized forged non-disclosure agreements and began with a convincing WhatsApp message from someone posing as a known executive. This tactic exploited corporate communication channels and safeguards, leading to a significant financial loss for the victimized company. The operation highlights vulnerabilities in corporate acquisition processes and the potential for financial exploitation by threat actors. As of now, the incident is under investigation, and organizations are advised to enhance their verification protocols for financial transactions.

Key Points: • Phantom Deal scam resulted in a €626,735.45 loss to a targeted corporation. • Attackers used forged NDAs and impersonated executives via WhatsApp. • The operation reveals vulnerabilities in corporate acquisition processes.

Timeline

2026-09-03
Phantom Deal scam reported
Cybercriminals impersonated executives to execute a €626,735.45 wire transfer scam using fake NDAs.
Gbhackers
2026-09-03
Details of the scam revealed
The operation involved convincing a legal employee to bypass corporate safeguards under the guise of a confidential transaction.
Cybersecuritynews