# "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs

> A financially motivated, malware-free business-email/WhatsApp-compromise campaign dubbed "Phantom Deal" impersonates real executives and forges branded NDAs (PwC, KPMG, Ogier) to fabricate a secret-acquisition pretext, isolate legal and finance staff from internal verification, and pressure large enterprises into wiring six-figure advance-fee payments to a Hong Kong beneficiary. Gen Digital uncovered the campaign after a failed €626,735.45 attempt against its own Avast Software entity and identified at least four other targets across private equity, industrial finance, sales, mining, and energy.

- **Published:** 2026-09-03T00:00:00Z
- **Last reviewed:** 2026-09-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2322
- **ID:** TL-2026-2322
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Phantom Deal is a financially motivated fraud campaign that abuses the trust dynamics of real corporate M&A processes rather than any software vulnerability or malware. The operation was uncovered by Gen Digital (the parent of Avast and NortonLifeLock) after an attacker contacted a member of its legal team, an employee referred to as "David" in Gen's writeup, via WhatsApp. The message used the real name and photograph of a Dublin-based Gen executive along with an Irish-format phone number, and initially made no mention of money, acquisitions, or urgency — it simply asked whether the target was available to talk. When the operators later followed up with a phone call, the employee recognized that the caller's voice did not match the real executive, an early red flag that ultimately exposed the fraud.

After contact was established, a second impersonated persona, presented as a professional affiliated with PwC, requested the target's personal email address and subsequently delivered a polished, PwC-branded non-disclosure agreement describing a confidential acquisition. The forged NDA imposed strict secrecy provisions, instructing the recipient to communicate exclusively via WhatsApp and personal email and explicitly discouraging any discussion with colleagues in Legal, Finance, Treasury, Compliance, or Corporate Development — the very functions that would normally validate such a request. The fabricated narrative borrowed real corporate history for credibility, referencing NortonLifeLock's actual September 2022 acquisition of Avast Software (the deal that formed Gen Digital) and inventing a fictitious follow-on "secret acquisition" with a claimed public-announcement date of June 19, 2026.

Having isolated the target from internal verification channels, the attackers demanded a wire transfer of €626,735.45, framed as an "Advance Retainer for Professional Services" and payable from Avast Software s.r.o. to a company registered in Hong Kong, with the fictitious promise of reimbursement as an intercompany receivable once the (nonexistent) acquisition was publicly announced. To simulate legitimacy and monitor progress toward payout, the operators pressed for SWIFT MT103 execution confirmations and UETR (Unique End-to-End Transaction Reference) payment-tracking data. The Gen employee identified inconsistencies in the stated legal rationale for why Avast Software should be paying into an arrangement tied to NortonLifeLock Ireland Limited, and no funds were transferred.

Gen Digital's subsequent investigation found the attempt against it was not isolated: at least four other individuals at separate organizations — spanning private equity, industrial finance, sales, mining, and energy — had received closely related NDAs. Although the employers and the specific advisory firm impersonated differed (with KPMG and the offshore law firm Ogier also used as forged NDA brands alongside PwC), the documents shared identical structure, confidentiality language, and template traces, indicating a reusable fraud package rather than a one-off social-engineering attempt. None of the impersonated firms (PwC, KPMG, or Ogier) were compromised or otherwise involved; their brands were used without their knowledge purely to add credibility to the forged documents. The campaign demonstrates that large-enterprise M&A and payment-approval workflows remain exploitable through confidentiality-driven isolation alone, with no need to defeat endpoint security, compromise a mailbox, or deploy any malicious code.

## MITRE ATT&CK

- T1589.003 Employee Names
- T1591.004 Identify Roles
- T1593.001 Social Media
- T1598.001 Spearphishing Service
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1566.003 Spearphishing via Service
- T1591.002 Business Relationships
- T1684.001 Impersonation
- T1090 Proxy
- T1657 Financial Theft

## Sources

- [Large Enterprises Face Fake Merger & Acquisition Scams](https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams)
- [Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers](https://cybersecuritynews.com/phantom-deal-hackers/)
- [Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Wire Transfer](https://gbhackers.com/fake-acquisition-scam/)
- [Hackers Pose as Executives and Use Fake NDAs to Steal Corporate Wire Transfers](https://cyberpress.org/fake-ndas-drain-corporate-payments/)
- [Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers](https://www.cryptika.com/phantom-deal-hackers-impersonate-executives-and-use-fake-ndas-to-steal-corporate-wire-transfers/)
- [NortonLifeLock Ireland Limited and Avast Software: Hackers Pose as Executives in Fake NDA Scam](https://blog.rankiteo.com/avagen1788434875-nortonlifelock-ireland-limited-avast-software-cyber-attack-september-2026/)
- [NortonLifeLock Completes Merger with Avast](https://newsroom.gendigital.com/2022-09-12-NortonLifeLock-Completes-Merger-with-Avast)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2322
