Phantom Deal Scam Uses Fake M&A Lures to Dupe Enterprise Finance Staff
A sophisticated business email compromise (BEC) operation dubbed "Phantom Deal" is targeting midlevel employees at large enterprises, leveraging highly convincing fake merger and acquisition communications to trick victims into initiating unauthorized wire transfers. According to researchers, the threat actors behind the campaign are conducting extensive reconnaissance on victim organizations, studying internal communications, executive relationships, and corporate transaction patterns to craft believable pretexts that pass casual scrutiny.
Unlike generic phishing blasts, Phantom Deal operators tailor each lure to the target's specific business context, referencing real projects, plausible counterparties, and authentic-sounding deal structures. Midlevel finance and operations staff — employees with sufficient payment authority but who may bypass executive scrutiny — are the primary targets. Once contact is established, attackers guide victims through a multi-stage process that typically culminates in a request to route funds to attacker-controlled accounts disguised as legal escrow or closing-cost payments.
The campaign reflects a broader trend of adversaries investing significant time in open-source intelligence gathering, including review of corporate websites, SEC filings, and leaked credentials to build credible social engineering pretexts. Defenders are advised to verify any M&A-related payment requests through a secondary, out-of-band channel, and employees should routinely check whether their corporate credentials have appeared in known exposures using an email breach checker before adversaries can weaponize them. Organizations can also audit their public-facing domain footprint with a WHOIS lookup to identify suspicious registrations mimicking corporate brands, and mandate phishing-resistant authentication to reduce the impact of credential theft.
Security teams should treat unsolicited M&A outreach as a high-risk indicator, enforce dual-approval workflows for wire transfers above set thresholds, and run continuous phishing simulations that mimic the long-con tactics used by groups like the Phantom Deal operators.