HomeCyber BalkansFake Acquisition Scam Targets Companies with Forged NDAs to Extract €626,000 Payment

Fake Acquisition Scam Targets Companies with Forged NDAs to Extract €626,000 Payment

Published on

spot_img

Business Email Compromise Scheme: The Phantom Deal

In a sophisticated business email compromise operation, threat actors impersonated executives from Gen and major consulting firms to execute a fraudulent scheme that resulted in the attempted illicit transfer of €626,735.45 to a Hong Kong entity. This operation, dubbed "Phantom Deal," highlights the alarming tactics utilized by financially motivated hackers who can exploit legitimate mergers and acquisitions (M&A) processes without resorting to malware, software vulnerabilities, or direct compromises of email accounts.

The primary aim of these actors was not to bypass endpoint security systems but rather to manipulate an employee into ignoring the internal checks that are typically in place to prevent fraudulent transactions. The impersonation was meticulous; the profile of the alleged executive used a real name, an authentic photograph, and an Irish phone number, initially avoiding mentions of money, acquisitions, or urgency, which could raise immediate eyebrows.

The targeted individual, identified by Gen as “David” and a member of the company’s legal team, had personal acquaintanceship with the executive being impersonated. This personal connection created an initial layer of trust, but an unfamiliar phone number did trigger skepticism. A subsequent phone call clarified that the voice on the line did not belong to the genuine executive, sparking further suspicion.

Following this, the fraudsters introduced another fictitious persona, representing a supposed professional from PwC. This fake identity requested David to shift their conversation to a personal email account—a strategic move designed to transition the operation to a more discreet channel, ultimately facilitating the delivery of a forged non-disclosure agreement (NDA).

The fraudulent NDA, branded with PwC’s insignia, falsely claimed the existence of a confidential acquisition and included stringent secrecy provisions. It directed David to use WhatsApp and personal email for further communications while advising against discussions with colleagues in Legal, Finance, Treasury, Compliance, or Corporate Development. Such instructions aimed to isolate David under the guise of contractual obligation, thereby manipulating normal corporate confidentiality practices to stifle independent verification.

Building upon the façade of a genuine acquisition, the impersonators exploited historical corporate ties, referencing Avast Software and NortonLifeLock Ireland Limited—entities previously linked through NortonLifeLock’s acquisition of Avast in 2022, which eventually had a role in forming Gen Digital. This context made the fraudulent request seem more plausible and lent credibility to the proposal for an intercompany payment.

Gen Researchers reported that the initial stage of the scam began with what appeared to be a standard WhatsApp message from someone posing as a legitimate Gen executive based in Dublin. However, David’s acute awareness of internal legal and transaction processes ultimately thwarted the attackers’ attempts to proceed with the illicit transaction when inconsistencies regarding payment claims for Avast Software s.r.o. were identified.

The fraudsters persisted, instructing Avast Software s.r.o. to transfer the substantial amount to a company in Hong Kong, labeling it as an “Advance Retainer for Professional Services” and portraying it as an intercompany receivable that would be reimbursed post-announcement of the acquisition. To induce urgency, they claimed the transaction would be announced on June 19, 2026, and repeatedly requested detailed SWIFT MT103 transaction messages—commonly used as proof of international wire transfers—as well as the Unique End-to-End Transaction Reference (UETR) for tracking purposes.

These requests indicated a calculated effort to confirm that funds were in motion, along with sufficient information to monitor the payment before any intervention from bank or corporate treasury teams. Once Gen identified the fraudulent operation, the research team opted to engage with the attackers while employing a controlled approach, providing them with a forged account statement and a falsified Citibank-style payment confirmation email equipped with a tracked link protected by a canary token.

The token tracked 49 HTTP requests originating from 43 different IP addresses within a span of 24 days. Initial traffic largely stemmed from automated scanners and cloud services, but as the investigation progressed, Gen identified repeated access through VPNs, proxies, and non-hosting ISP connections, which suggested a manual effort by individuals involved in the fraudulent operation.

Although the gathered telemetry was inadequate for attributing the fraud to specific parties, it did reveal a persistent interest in the fabricated payment confirmation. In subsequent investigations, Gen uncovered four additional targets who had received similar NDA documents, involving senior personnel across private equity, industrial finance, sales, mining, and energy sectors.

While the forged documents employed varied narratives and impersonated advisors from firms such as PwC, KPMG, and Ogier, they maintained consistent wording, secrecy clauses, and unusual numerical identifiers. Notably, Gen stated that there is no evidence suggesting that any of the advisory firms were compromised or involved in the operation.

This incident serves as a stark reminder of the emerging risks facing legal, finance, and M&A teams. While NDAs serve crucial purposes, they must not inhibit the authentication of payment instructions. Any proposal that shifts communication to platforms like WhatsApp or personal email, enforces exceptional confidentiality, or solicits crucial transaction data should immediately trigger a verification process through established corporate contacts and banking controls. The Phantom Deal underscores the necessity for heightened vigilance against potential threats that leverage legitimate business channels for fraudulent gains.

Source link

Latest articles

CISA Includes Seven Exploited Flaws as Attackers Use Reverse Shells and Crypto Miners

On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of...

FBI Investigates Potential Breach Involving 153 Million Driver’s Licenses

The FBI is currently investigating a potentially vast breach of identity data affecting as...

Trump Cyber Program May Impact Legal Protections for Companies

New White House Program May Strip Providers of Legal Threat Sharing Protections In a significant...

US and Canadian Court Records Compromised After Thomson Reuters Incident

Cybersecurity Incident at Thomson Reuters Affects Court Management Software, Exposing Sensitive Case Data Thomson Reuters...

More like this

CISA Includes Seven Exploited Flaws as Attackers Use Reverse Shells and Crypto Miners

On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of...

FBI Investigates Potential Breach Involving 153 Million Driver’s Licenses

The FBI is currently investigating a potentially vast breach of identity data affecting as...

Trump Cyber Program May Impact Legal Protections for Companies

New White House Program May Strip Providers of Legal Threat Sharing Protections In a significant...