VYPR
breachPublished Sep 3, 2026· 1 source

Phantom Deal Hackers Exploit Social Engineering and Fake NDAs for Wire Transfer Fraud

Cybercriminals are using a sophisticated social engineering campaign dubbed 'Phantom Deal' to trick employees into initiating fraudulent wire transfers for non-existent acquisitions, bypassing traditional security measures.

A new financial fraud campaign, dubbed "Phantom Deal," is leveraging social engineering tactics to trick corporate employees into initiating large wire transfers for fake acquisitions. Unlike traditional attacks that rely on malware or phishing links, this operation uses impersonated executives on platforms like WhatsApp, combined with fabricated Non-Disclosure Agreements (NDAs), to create a sense of urgency and confidentiality that bypasses standard security protocols.

The campaign's effectiveness stems from its meticulous approach to impersonation and its exploitation of legitimate business processes. Attackers initiate contact via WhatsApp, posing as familiar executives and using believable deal language. They then isolate the target employee, often directing them to communicate via personal email and a PwC-branded NDA. This NDA, while appearing legitimate, contains strict confidentiality clauses designed to prevent the employee from discussing the supposed transaction with colleagues, including finance and legal departments.

Researchers at Gen Digital identified the campaign after an attacker contacted a member of their legal team, impersonating a Dublin-based executive. The employee, noticing discrepancies in the caller's voice, collaborated with researchers to document the attempt. This investigation uncovered four other targeted individuals who had received similar NDAs, all sharing a common structure and template, indicating a reusable fraud package.

The attackers' methodology involves a multi-stage social engineering process. After establishing contact on WhatsApp, they request a personal email address. Subsequently, a seemingly official NDA is sent, which explicitly instructs the recipient to conduct all communications regarding the acquisition solely through WhatsApp and personal email, thereby circumventing official corporate channels. This tactic mirrors known CEO fraud schemes that leverage restricted communication to isolate victims.

In one documented instance, the attackers instructed Avast Software s.r.o. to transfer €626,735.45 to a Hong Kong-based company, ostensibly as an "Advance Retainer for Professional Services." The attackers framed this as an intercompany receivable to be reimbursed later, disguising a straightforward advance-payment fraud within familiar financial terminology. They further demanded a SWIFT MT103 message and a UETR payment-tracking reference, likely to monitor the transfer's progress and limit intervention time.

The "Phantom Deal" campaign highlights a significant shift in attack vectors, moving away from technical exploits towards exploiting human trust and established business workflows. Traditional security measures focused on detecting malware or suspicious links may be ineffective against this type of attack, as it operates entirely within seemingly legitimate business communications.

To counter such threats, security experts emphasize the importance of independent verification for all payment instructions. Employees should always use independently established contact methods to confirm any requests, especially those involving financial transactions or sensitive information, rather than relying on details provided within the suspicious communication. Verifying an advisor's identity through official directories is also crucial.

The core lesson from the "Phantom Deal" campaign is that while NDAs can mandate confidentiality, they do not negate the necessity of authenticating transactions. Independent confirmation before executing any cross-border transfer remains a vital control, even when the initial contact occurs outside of traditional email channels. This approach is critical as cybercriminals increasingly employ sophisticated social engineering tactics that can appear more trustworthy than conventional phishing attempts.

Synthesized by Vypr AI