Threat reportPhishingTL-2026-2322
"Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs
"Phantom Deal" (TL-2026-2322), also tracked as Phantom Deal, is a high-severity phishing campaign, first published 2026-09-03. It has no confirmed attribution, maps to 11 MITRE ATT&CK techniques (T1090, T1566.003, T1585.001), and is covered by 9 detection rules and 10 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-2322
- Threat ID
- TL-2026-2322
- Also known as
- Phantom Deal
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, cybersecurity, private equity, industrial finance, sales, mining, energy
- Target regions
- Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 10
How "Phantom Deal" works
A financially motivated, malware-free business-email/WhatsApp-compromise campaign dubbed "Phantom Deal" impersonates real executives and forges branded NDAs (PwC, KPMG, Ogier) to fabricate a secret-acquisition pretext, isolate legal and finance staff from internal verification, and pressure large enterprises into wiring six-figure advance-fee payments to a Hong Kong beneficiary. Gen Digital uncovered the campaign after a failed €626,735.45 attempt against its own Avast Software entity and identified at least four other targets across private equity, industrial finance, sales, mining, and energy.
Phantom Deal is a financially motivated fraud campaign that abuses the trust dynamics of real corporate M&A processes rather than any software vulnerability or malware. The operation was uncovered by Gen Digital (the parent of Avast and NortonLifeLock) after an attacker contacted a member of its legal team, an employee referred to as "David" in Gen's writeup, via WhatsApp. The message used the real name and photograph of a Dublin-based Gen executive along with an Irish-format phone number, and initially made no mention of money, acquisitions, or urgency — it simply asked whether the target was available to talk. When the operators later followed up with a phone call, the employee recognized that the caller's voice did not match the real executive, an early red flag that ultimately exposed the fraud.
After contact was established, a second impersonated persona, presented as a professional affiliated with PwC, requested the target's personal email address and subsequently delivered a polished, PwC-branded non-disclosure agreement describing a confidential acquisition. The forged NDA imposed strict secrecy provisions, instructing the recipient to communicate exclusively via WhatsApp and personal email and explicitly discouraging any discussion with colleagues in Legal, Finance, Treasury, Compliance, or Corporate Development — the very functions that would normally validate such a request. The fabricated narrative borrowed real corporate history for credibility, referencing NortonLifeLock's actual September 2022 acquisition of Avast Software (the deal that formed Gen Digital) and inventing a fictitious follow-on "secret acquisition" with a claimed public-announcement date of June 19, 2026.
Having isolated the target from internal verification channels, the attackers demanded a wire transfer of €626,735.45, framed as an "Advance Retainer for Professional Services" and payable from Avast Software s.r.o. to a company registered in Hong Kong, with the fictitious promise of reimbursement as an intercompany receivable once the (nonexistent) acquisition was publicly announced. To simulate legitimacy and monitor progress toward payout, the operators pressed for SWIFT MT103 execution confirmations and UETR (Unique End-to-End Transaction Reference) payment-tracking data. The Gen employee identified inconsistencies in the stated legal rationale for why Avast Software should be paying into an arrangement tied to NortonLifeLock Ireland Limited, and no funds were transferred.
Gen Digital's subsequent investigation found the attempt against it was not isolated: at least four other individuals at separate organizations — spanning private equity, industrial finance, sales, mining, and energy — had received closely related NDAs. Although the employers and the specific advisory firm impersonated differed (with KPMG and the offshore law firm Ogier also used as forged NDA brands alongside PwC), the documents shared identical structure, confidentiality language, and template traces, indicating a reusable fraud package rather than a one-off social-engineering attempt. None of the impersonated firms (PwC, KPMG, or Ogier) were compromised or otherwise involved; their brands were used without their knowledge purely to add credibility to the forged documents. The campaign demonstrates that large-enterprise M&A and payment-approval workflows remain exploitable through confidentiality-driven isolation alone, with no need to defeat endpoint security, compromise a mailbox, or deploy any malicious code.
MITRE ATT&CK techniques used in TL-2026-2322
Command and Control
Initial Access
T1566.003 Spearphishing via Service
Resource Development
T1585.001 Social Media Accounts; T1585.002 Email Accounts
Reconnaissance
T1589.003 Employee Names; T1591.002 Business Relationships; T1591.004 Identify Roles; T1593.001 Social Media; T1598.001 Spearphishing Service
Impact
Defense Evasion
Remediation for "Phantom Deal"
Patches
- Not applicable — Phantom Deal exploits business-process trust and human decision-making rather than a software vulnerability; no patch exists or is required.
Immediate actions
- Independently verify any executive request received via WhatsApp or personal email by calling the executive back on a known, pre-established corporate phone number before taking any action.
- Escalate any inbound M&A or deal-secrecy NDA that instructs recipients to bypass Legal, Finance, Treasury, or Compliance to the internal fraud/security team before responding.
- Hold any wire transfer whose instructions request SWIFT MT103 execution confirmation or a UETR reference until the payment instruction is verified through an independently established channel.
Workarounds
- Treat any professional-services NDA that forbids consulting Legal, Finance, or Compliance before payment as presumptively fraudulent, and refuse to act on it until independently authenticated with the named advisory firm (e.g., PwC, KPMG, Ogier) through their official contact channels rather than the ones supplied in the document.
Longer-term hardening
- Establish a documented out-of-band callback policy for all wire-transfer and M&A-related payment requests, using contact details sourced from internal directories rather than the requesting message or document.
- Train Legal, Finance, and Treasury staff on Phantom Deal-style pretexts: a confidentiality clause used to suppress internal verification is a fraud red flag, not a legitimate legal obligation.
- Require dual-approval and a mandatory cooling-off period for any large wire transfer tied to an undisclosed or confidential acquisition.
Timeline of "Phantom Deal"
- NortonLifeLock completes its acquisition of Avast Software, forming Gen Digital — the real corporate-history fact later weaponized inside the forged Phantom Deal NDA to lend the fictitious "secret acquisition" narrative credibility.
- Attackers embed a claimed (fictitious) public-announcement date of June 19, 2026 into the forged NDA's confidential-acquisition narrative to create false urgency and a plausible repayment timeline for the requested advance.
- Gen Digital publishes its research on the campaign ("The NDA Was the Payload: Inside Phantom Deal") and the findings are reported by Dark Reading, Cybersecuritynews, GBHackers, and other outlets.
- Gen Digital observes 49 HTTP requests from 43 distinct IP addresses over a 24-day monitoring window after embedding a tracked link inside a fake payment-confirmation email; early hits originate from automated scanners, cloud services, and redirect-analysis infrastructure, followed by manual engagement routed through VPNs, proxies, and non-hosting-provider internet connections.
- Gen Digital's investigation identifies four additional targeted individuals across private equity, industrial finance, sales, mining, and energy who received structurally related forged NDAs invoking PwC, KPMG, and Ogier branding, indicating a reusable fraud template.
- The targeted Gen legal-team employee identifies inconsistencies in the stated rationale for the payment and declines to proceed; no funds are transferred.
- Attackers demand a €626,735.45 wire transfer from Avast Software s.r.o. to a Hong Kong-based entity, framed as an "Advance Retainer for Professional Services," and press for SWIFT MT103 execution confirmation and a UETR tracking reference.
- A polished, PwC-branded NDA describing a confidential acquisition is delivered, instructing the target to communicate only via WhatsApp and personal email and not to discuss the matter with Legal, Finance, Treasury, Compliance, or Corporate Development.
- A second impersonated identity, presented as a professional affiliated with PwC, is introduced and requests the target's personal email address to continue the exchange outside corporate channels.
- A follow-up phone call from the impersonator exposes the fraud attempt when the targeted employee recognizes that the caller's voice does not match the real executive being impersonated.
- As documented in Gen Digital's disclosure, an impersonator opens contact with a Gen legal-team employee via WhatsApp, using the real name and photograph of a Dublin-based Gen executive and an Irish-format phone number, with no initial mention of money or urgency.
Sources cited for "Phantom Deal"
- Large Enterprises Face Fake Merger & Acquisition Scams
- Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers
- Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Wire Transfer
- Hackers Pose as Executives and Use Fake NDAs to Steal Corporate Wire Transfers
- Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers
- NortonLifeLock Ireland Limited and Avast Software: Hackers Pose as Executives in Fake NDA Scam
- NortonLifeLock Completes Merger with Avast
Detection coverage for TL-2026-2322
As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2322 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.