Cybercriminals have devised a new scheme, dubbed the Phantom Deal, to manipulate employees into authorizing substantial wire transfers under the guise of fake acquisition deals. This sophisticated campaign begins with a seemingly innocuous WhatsApp message from an individual masquerading as a known company executive.
Understanding the Phantom Deal Scam
The scam operates by circumventing typical corporate security measures, presenting them as obstacles to a confidential transaction that must be bypassed. Unlike traditional cyber attacks, this scheme does not rely on malware or compromised mailboxes. Instead, it leverages real names, photographs, company backgrounds, and familiar deal language to give the fake transaction an air of legitimacy.
Researchers at Gen Digital uncovered this campaign when a member of their legal team received a suspicious call from someone impersonating a Dublin-based executive. The employee noticed the caller’s voice didn’t match the executive’s and opted to collaborate with researchers to document the incident rather than proceed with the transfer.
The Role of Fake NDAs in Corporate Fraud
According to a Gen Digital report shared with Cyber Security News, the investigation identified four additional targets who received similar non-disclosure agreements (NDAs). Despite differences in the alleged companies and advisers involved, the NDAs shared identical structures and confidentiality clauses, indicating a standardized fraud model targeting individuals involved in corporate transactions.
The fraudulent process begins with an innocuous WhatsApp message, followed by a request for a personal email address from an impersonated professional reportedly linked to PwC. The victim then receives a convincingly branded NDA, outlining a secret acquisition and stringent disclosure rules, directing all discussions to personal channels, bypassing official communication systems.
Preventing Future Financial Scams
Payment instructions within the scheme directed Avast Software s.r.o. to transfer over €600,000 to a Hong Kong account as an “Advance Retainer for Professional Services.” The criminals claimed the amount would be documented as an intercompany receivable and reimbursed post-announcement, wrapping the fraud in legitimate-sounding finance terms.
Researchers emphasize the importance of independent verification of payment instructions through pre-established contact methods. This step is crucial to thwart schemes where fraudsters send authenticated phishing messages that appear more credible than typical spam. Ensuring the authenticity of requests before proceeding with cross-border transfers can prevent such frauds.
The lesson is clear: while NDAs may restrict the dissemination of transaction details, they cannot replace the need for verification. With the rise of business email compromise attacks, maintaining stringent security controls is essential, even when scams originate outside conventional inboxes.
Stay informed about active malware and phishing threats by updating your Security Operations Center (SOC) promptly. Tools like ANYRUN can aid in early threat detection and incident prevention.
