TechNewsReel
Live

Phantom Deal: M&A Scams Target Senior Executives with Fake NDAs

Threat actors use detailed corporate reconnaissance and impersonated professional services firms to trick employees into making massive unauthorized transfers.

TechNewsReel Newsroom · September 3, 2026

A highly targeted social engineering campaign dubbed "Phantom Deal" is targeting senior corporate employees, using fabricated merger and acquisition (M&A) scenarios to trigger large financial transfers. The attackers impersonate high-level executives and professional services firms to deceive targets into bypassing standard corporate payment controls.

According to reporting from Dark Reading, the campaign utilizes detailed reconnaissance of a company's public data and corporate history to build plausible narratives. In one notable instance, Gen—the parent company of Norton and Avast—thwarted an attempt to transfer €626,735.45 to a company based in Hong Kong. Gen security researchers identified at least five different targets of the campaign by analyzing metadata embedded within a fake non-disclosure agreement (NDA).

The Mechanics of Deception

The attackers target senior staff across a wide array of sectors, including energy, mining, sales, industrial finance, and private equity. To maintain the illusion of a legitimate, confidential deal, the threat actors move communications off official corporate channels and onto WhatsApp.

To enforce this secrecy, the campaign employs fake NDAs branded with the logos of prestigious professional services firms, including KPMG, PwC, and Ogier. These documents serve a dual purpose: they provide a veneer of legitimacy to the fake deal and justify the requirement for absolute confidentiality, which prevents the target from verifying the request through internal company channels.

Why This Narrative Works

This campaign represents an evolution of the traditional "advance fee scam," tailored specifically for the corporate environment. By referencing actual corporate events—such as the 2022 merger between Avast and NortonLifeLock—attackers create a believable context that makes urgent, non-standard financial requests seem logical to the victim.

This approach highlights a critical vulnerability in corporate trust markers. When a narrative is sufficiently tailored to an organization's actual history, even trained employees may overlook red flags. Luis Corrons, a security evangelist at Gen, noted that these scams are becoming so convincing that "even the most trained eye can have trouble spotting them."

Industry Implications

The sophistication of Phantom Deal demonstrates that public information is being weaponized to bypass traditional security awareness training. It proves that "security through obscurity" is ineffective, as attackers can now synthesize public records into high-fidelity social engineering lures.

For the broader industry, this underscores a failure in payment control processes. The ability of an attacker to nearly move over €600,000 based on a WhatsApp conversation and a fake PDF suggests that many enterprises still rely too heavily on the perceived identity of the requester rather than the legitimacy of the process.

What to Watch

As these campaigns evolve, organizations should focus on verifying the process rather than the person. As Corrons advised, employees should not just ask whether a contact looks legitimate, but whether the process they are being asked to follow is legitimate.

Security teams should remain vigilant for unusual communication patterns involving senior executives and the use of third-party messaging apps for sensitive corporate transactions. The discovery of the five targets via metadata suggests the campaign is ongoing and likely expanding its target list.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.