news.mlab.sh
Back to the feed
threat-intel

Large Enterprises Targeted in Fake Merger & Acquisition Scams

High
Summary

Threat actors are using sophisticated social engineering tactics, mimicking corporate mergers and acquisitions, to trick employees into transferring large sums of money to fraudulent accounts. The campaign, dubbed “Phantom Deal,” is highly targeted, leveraging publicly available information about companies and their employees to build convincing narratives. Gen, a cybersecurity company, was successfully defended when an employee noticed inconsistencies in the attacker’s story and voice. The campaign has targeted at least five companies, including those in private equity, industrial finance, sales, mining, and energy, using firms like PwC and KPMG to facilitate the scams. The key to defense lies in employee awareness and rigorous verification processes, not relying on obscurity.

Threat actors are employing a new generation of social engineering, mimicking corporate mergers and acquisitions, to deceive employees into initiating large financial transfers. The campaign, known as “Phantom Deal,” is highly targeted, meticulously gathering information about companies and their employees from publicly available sources to construct believable scenarios. Gen, a cybersecurity firm, was successfully defended when an employee noticed discrepancies in the attackers’ narrative and voice.

The campaign began with a series of emails impersonating executives, referencing real corporate history, such as NortonLifeLock’s acquisition of Avast in 2022. Attackers then leveraged this context to request payments on behalf of NortonLifeLock Ireland Limited, supposedly connected to a confidential acquisition and reimbursable when the deal was announced. A second threat actor impersonated a middleman at PricewaterhouseCoopers (PwC), providing a non-disclosure agreement (NDA) with PwC branding, further solidifying the illusion of a legitimate corporate transaction.

The attackers then requested a specific €626,735.45 Euro transaction to be sent to a company in Hong Kong, a detail that initially seemed plausible given the fabricated context. However, the employee’s careful scrutiny and a phone call to verify the executive’s identity exposed the fraud. Gen subsequently drafted a fake transaction confirmation email, complete with a tracking token, to maintain the attackers’ belief in their success.

Researchers identified at least five other targets of the same campaign, including companies in private equity, industrial finance, sales, mining, and energy, each receiving a highly customized attack tailored to their specific circumstances and utilizing firms like PwC and KPMG to facilitate the scams. The success of these attacks hinged on the attackers’ ability to gather detailed information about their targets – names, photographs, job roles, and acquisition history – all readily available on the public internet.

Despite this readily available information, security through obscurity is not a viable solution. The key to defense lies not in hiding information, but in employee awareness and rigorous verification processes. The hero of Gen’s story, “David,” successfully thwarted the attack by verifying the person behind the email and understanding what a legitimate transaction should look like, rather than blindly trusting the presented identity. Companies should encourage employees to report suspicious activity rather than attempting to bypass established verification controls.

Read the full article at Dark Reading