A sophisticated scam dubbed “Phantom Deal” is targeting corporations by impersonating executives and using faux NDAs (non-disclosure agreements) to push employees into executing large international wire transfers. Unlike typical corporate fraud that uses malware or stolen credentials, this scheme relies instead on social engineering and procedural manipulation. Cybercriminals are abusing business norms—real names, known executives, familiar legal documents—to craft a convincing but entirely fictional acquisition scenario.
The operation begins with an innocuous WhatsApp message from someone posing as a senior executive. Once the employee responds, a secondary contact portraying an adviser from a major consulting firm—branded to look like PwC—is engaged. That adviser sends a polished, firm-branded NDA that frames the acquisition as highly confidential. The document demands that discussions occur only via WhatsApp or personal email, expressly discouraging any communication via corporate legal, finance, treasury, or compliance channels.
The next move is the financial ask: a transfer is requested—often in the hundreds of thousands of euros—to an entity overseas, typically under the guise of an “advance retainer for professional services.” For example, in one case Avast Software s.r.o. was asked to send €626,735.45 to a firm in Hong Kong, with the promise that the amount would be booked as an intercompany receivable and reimbursed later. After the transfer, the fraudsters request a SWIFT MT103 payment confirmation and the UETR tracking reference—tools that make it harder for institutions to stop or reverse the payment.
How It Evades Detection
Researchers found no signs of compromised email accounts or malware in any of the incidents. Instead, the fraud relies on manipulating standard business processes—convincing a target that confidentiality overrides internal controls. Restricting access to outside official channels, using familiar corporate branding, and leveraging known names all serve to build trust. Using insider knowledge gives the scheme its power.
A pattern of repeated documents was discovered: across multiple targets, the NDAs shared the same language, layout, and confidentiality clauses, even when the organizations or advisors differed. This points to a reuse of tools and templates in widespread campaigns aimed at employees involved in financial transactions.
Red Flags, Prevention, and Corporate Lessons
Several warning signs emerged from the Gen Digital investigation. These include: requests to move conversations off official channels, insistence on personal email or apps like WhatsApp, and blocking involvement of legal or compliance teams. Asking for payment instructions via channels that were not verified ahead of time is another major indicator.
To counter these threats, organizations are advised to establish verification processes rooted in pre-existing contact points—such as directories or institutional phone numbers—before executing any wire transfers. Even if an NDA seems legitimate, it doesn’t replace the need for authentication of identities and requests. Security tools often focus heavily on malware or phishing via email, but attacks like “Phantom Deal” begin outside those vectors.
Companies should also train employees to spot schemes that borrow heavy legitimacy—using named executives, recognizable firms like consulting or advisory companies, and realistic documentation. Internal alignment between legal, finance, compliance, and executive leadership is vital so one department doesn’t get isolated.
This tactic echoes broader trends in social engineering and business email compromise, but with no compromised inbox at the start. It demonstrates that even the most cautious organizations can be vulnerable when their internal processes are bypassed. As cross-border transfers become instantly auditable via messages like SWIFT MT103 and UETR, attackers are pushing speed to their advantage.
Analytical Angle:The Phantom Deal campaign underlines how fraudsters are weaponizing legitimate business tools—executive names, institutional branding, NDAs—and leveraging company culture to override controls. It’s a reminder that cybersecurity isn’t just about tech—governance, process integrity, and verified communication channels can make the difference between safety and crisis. As international finance gets faster and more automated, organizations should budget just as much for procedural hygiene and human verification as they do for firewalls and endpoint protections. Watch for recurrent NDA templates, offline communication requests, and unusual channels for payment instructions—those are the danger signals this scheme thrives on.