Large Enterprises Targeted in Fake Merger & Acquisition Scams
The 'Phantom Deal' BEC campaign uses deep OSINT on target companies to fabricate convincing M&A scenarios, tricking midlevel employees into initiating large wire transfers — a social-engineering evolution beyond generic invoice fraud.
Summary written by editorial AI · Source link below
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Editorial Analysis
Framed for the CISO & Security Leaders desk
The 'Phantom Deal' campaign targets midlevel employees during M&A activity — a period of heightened trust and urgency that amplifies business-email-compromise risk.
Issue targeted awareness guidance to finance and M&A teams and require multi-party authorisation for all large transfers during deal activity.
A sophisticated fraud campaign impersonates merger activity to trick employees into transferring large sums — deal teams need specific countermeasures.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d