Phantom Deal Hackers Impersonate Execs, Use Fake NDAs to Steal Wire Transfers
Key Takeaways A new social engineering campaign, dubbed “Phantom Deal,” is targeting employees with fake acquisition deals to trick them into making large wire transfers. The attackers...
Key Takeaways
- A new social engineering campaign, dubbed “Phantom Deal,” is targeting employees with fake acquisition deals to trick them into making large wire transfers.
- The attackers impersonate senior executives and leverage convincing, but fraudulent, Non-Disclosure Agreements (NDAs).
- The scheme relies on social engineering and does not involve malware, compromised mailboxes, or malicious attachments.
- The fake NDAs instruct victims to communicate only through WhatsApp and personal email, bypassing standard corporate safeguards.
- Researchers successfully documented an attempt, preventing a transfer of €626,735.45.
A sophisticated social engineering campaign, identified as “Phantom Deal,” is actively deceiving corporate employees into initiating substantial wire transfers under the guise of confidential acquisition negotiations. This elaborate fraud begins with seemingly innocuous WhatsApp messages, impersonating known executives, and meticulously crafts a scenario designed to circumvent established corporate financial protocols.
Table Of Content
Instead of relying on typical cyberattack vectors like malware or compromised email accounts, the Phantom Deal operatives employ a highly effective blend of social engineering tactics. They utilize genuine names, photographs, company histories, and authentic-sounding deal terminology to construct a believable, yet entirely fabricated, transaction. This approach allows the financial attack to unfold within the context of routine business communications, making it particularly challenging to detect through conventional security measures, as detailed in a Gen Digital report.
Gen Digital analysts uncovered this campaign when an attacker targeted a member of their legal team, posing as a Dublin-based executive. The vigilant employee recognized a discrepancy in the caller’s voice compared to the impersonated colleague. This critical observation led the employee to collaborate with researchers, enabling them to document the attempted fraud rather than authorizing the requested funds.
The investigation further revealed that four other individuals had received similar fraudulent Non-Disclosure Agreements (NDAs). While the purported employers and advisors in these instances varied, the underlying documents consistently reused identical structures, confidentiality clauses, and template elements. This pattern strongly suggests the existence of a standardized, reusable fraud package specifically designed to target individuals involved in corporate transactions.
Phantom Deal Modus Operandi
The initial contact in the Phantom Deal campaign is deliberately benign, typically a WhatsApp message inquiring about the recipient’s availability. Once a connection is established, a second impersonated individual, often presented as a professional affiliated with PwC, requests a personal email address. This step paves the way for the delivery of a highly polished, PwC-branded NDA, which outlines a fictitious secret acquisition and imposes stringent disclosure restrictions.
The fraudulent NDA serves a dual purpose beyond mere paperwork. It explicitly directs the recipient to conduct all discussions related to the acquisition exclusively via WhatsApp and personal email, effectively isolating them from internal colleagues and standard corporate communication channels. While strict confidentiality can be a legitimate aspect of real merger and acquisition deals, diverting critical requests away from approved company communication platforms is a significant red flag, echoing tactics seen in other WhatsApp CEO fraud tactics.
The fraudulent payment instructions directed Avast Software s.r.o. to transfer €626,735.45 to a Hong Kong-based company, labeling it as an “Advance Retainer for Professional Services.” The criminals further attempted to legitimize this demand by stating the sum would be recorded as an intercompany receivable and reimbursed post-announcement. This sophisticated language cloaked a basic advance-payment fraud in financial and legal jargon, designed to mislead experienced teams.
Subsequently, the attackers requested a SWIFT MT103, a banking message confirming an international transfer, and the UETR payment-tracking reference. These requests aimed to enable the criminals to monitor the transaction’s progress and potentially minimize the window for the victim company or bank to intervene and halt the transfer.
Independent Checks Break the Chain
Gen Digital’s research found no evidence of a compromised corporate mailbox or any technical exploit. The attack’s success hinged entirely on manipulating business processes, specifically convincing an employee that strict confidentiality necessitated bypassing established legal, finance, treasury, compliance, and corporate development controls. This means that cybersecurity teams solely focused on detecting malicious attachments or links could easily miss the initial stages of such an operation.
During the controlled interaction, researchers dispatched a fabricated payment-confirmation email containing a tracked link. This allowed them to record 49 HTTP requests originating from 43 distinct IP addresses over a period of 24 days. After filtering out automated scanners and cloud service traffic, the team still observed consistent access through various VPNs, proxies, and non-hosting internet connections, indicating active engagement from the attackers.
What You Should Do
- Independent Verification: Always verify payment instructions through a communication channel established independently of the current conversation. Do not rely on contact details provided within the suspicious message.
- Cross-Reference Information: If an advisor’s identity or a request seems unusual, consult official company directories or known contact information to confirm legitimacy.
- Be Wary of Secrecy Demands: Be highly suspicious of any request that demands extreme secrecy and attempts to bypass standard internal approval processes or communication channels, especially for financial transactions.
- Educate Employees: Conduct regular training for all employees, particularly those in legal, finance, and executive support roles, on sophisticated social engineering tactics like executive impersonation and advance-payment fraud.
- Implement Multi-Factor Authentication (MFA): Ensure MFA is enabled for all corporate accounts, especially those accessing financial systems or sensitive data.
- Review NDAs Critically: Train employees to scrutinize NDAs, especially those received unexpectedly or from unfamiliar sources, for unusual clauses regarding communication methods or payment instructions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.