Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Phantom Deal Fraud Uses Fake M&A Secrecy to Push a €626,000 Wire Transfer
Phantom Deal Fraud Uses Fake M&A Secrecy to Push a €626,000 Wire Transfer
Read Time:3 Minute, 9 Second

A social-engineering campaign dubbed Phantom Deal is wrapping straightforward payment fraud in the language and secrecy of corporate acquisitions. Attackers impersonate senior executives and professional advisers, move the conversation onto WhatsApp and personal email, and present a convincing non-disclosure agreement. The paperwork is designed to make bypassing colleagues and established payment controls feel like a legitimate requirement of a sensitive transaction.

Gen Digital documented the scheme after someone posing as a Dublin-based executive contacted a member of its legal team. The target noticed that a caller’s voice did not match the colleague whose identity was being used. Instead of following the payment request, the employee coordinated with investigators, giving them an opportunity to observe how the fraud progressed.

A harmless message establishes contact

The approach began with an ordinary WhatsApp question asking whether the recipient was at the office. After receiving a response, a second impersonated figure—presented as a professional connected to PwC—asked for a personal email address. The victim then received a polished, PwC-branded NDA describing a confidential acquisition and strict limits on disclosure.

The confidentiality terms performed a crucial psychological function. They instructed the employee to keep colleagues out of the discussion and use channels outside the company’s normal systems. Real mergers and acquisitions do involve restricted information, so the request borrowed a familiar business rule. The deception lay in turning legitimate discretion into an excuse to remove legal, treasury, compliance and corporate-development checks.

The request escalates to a six-figure payment

The attackers directed Avast Software s.r.o. to send €626,735.45 to a Hong Kong company, describing the money as an advance retainer for professional services. They claimed it would be booked as an intercompany receivable and repaid after the deal became public. Corporate terminology gave the request a plausible surface while concealing a conventional advance-payment scam.

Afterwards, the operators demanded a SWIFT MT103 message, which documents that an international payment was executed, along with the transaction’s UETR tracking reference. Those details could help criminals monitor progress and react quickly if a bank or the victim tried to recall the transfer.

A reusable fraud kit

Investigators found four other people who had received closely related NDAs. Although the alleged employers and advisers varied, the files shared structure, confidentiality language and template traces. That repetition suggests the campaign is a reusable playbook rather than an isolated attempt against a single company.

There was no evidence that the attackers had breached a corporate mailbox or delivered malware. During the controlled exchange, researchers sent a fake payment confirmation containing a tracked link. It recorded 49 requests from 43 IP addresses over 24 days, though scanners and cloud infrastructure inflated the raw total. Filtered activity still showed repeated access through VPNs, proxies and ordinary internet connections.

Independent verification breaks the spell

Traditional email controls may never see the opening message, and endpoint tools have no malicious attachment to block. Prevention depends on ensuring that confidentiality cannot override authentication or payment governance.

  • Confirm unusual payment instructions through a phone number or contact route established before the request.
  • Use the adviser’s official company directory, not details supplied in the WhatsApp conversation or NDA.
  • Require multiple approvers for new beneficiaries and large cross-border payments.
  • Treat demands for personal email, private messaging and exclusion of normal finance staff as linked warning signs.
  • Give employees a confidential escalation route for checking supposedly secret transactions.

The employee who noticed the mismatched voice demonstrated the value of contextual awareness. Artificially urgent secrecy should increase scrutiny, not reduce it. An NDA may determine who can know about a real transaction, but it cannot prove that the transaction or the people directing it are genuine. A brief, independently sourced confirmation can be the control that prevents six-figure losses.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Phantom Deal Fraud Uses Fake M&A Secrecy to Push a €626,000 Wire Transfer, use the discussion on Forum.

>> forum community

Comments

Leave a Reply