Large enterprises are being targeted by sophisticated cyber scammers in a campaign known as “Phantom Deal.” Threat actors are using social engineering tactics to convince mid-level employees to initiate large financial transfers, often under the guise of fake merger and acquisition deals. In some cases, these scams have been so convincing that even trained security professionals have struggled to spot them.
The scheme typically begins with an attacker identifying a key employee at the targeted company, usually someone in a position of authority such as a lawyer or accountant. They then send a phishing message via WhatsApp or email, pretending to be a high-ranking executive within the company. The message is friendly and non-descript, but it quickly becomes clear that something is amiss.
In one notable case, the attackers went so far as to create a fake non-disclosure agreement (NDA) from PricewaterhouseCoopers (PwC), complete with branding and language that would be familiar to even the most seasoned professionals. The NDA was designed to swear the employee to secrecy and limit their communication channels to WhatsApp and personal email addresses, effectively keeping the attackers under the radar.
Once the attacker has gained the trust of the employee, they will typically ask for a large financial transfer to facilitate the fake deal. In some cases, these requests have been as specific as €626,735.45 Euro, which is suspicious enough that even an untrained eye would raise an eyebrow. However, it’s worth noting that the attackers’ goal is not necessarily to steal money from the company, but rather to dupe the employee into initiating a large transfer.
The campaign has already claimed several victims, with at least five companies being targeted by the Phantom Deal scam. Luckily for Gen, the parent company of Norton and Avast, they were able to identify the attack in progress and draft a fake transaction confirmation email that tracked the attackers’ actions and connections.
What’s striking about this campaign is the level of sophistication displayed by the attackers. They have clearly done their homework, studying companies in extreme detail before launching their attacks. This is not your average run-of-the-mill phishing scam – these are highly customized operations designed to exploit specific vulnerabilities within each company.
The takeaway from this story is clear: no matter how convincing a scam may seem, it’s always worth taking a closer look. If an employee receives a message or email that seems suspicious, they should not hesitate to reach out to their superiors or IT department for guidance. By being vigilant and staying informed, companies can protect themselves against these types of attacks and avoid becoming the next victim of the Phantom Deal scam.
Source: Dark Reading — 2026-09-03