Large Enterprises Targeted in Fake Merger & Acquisition Scams
BLUF
Sophisticated M&A fraud campaigns are successfully bypassing traditional controls by targeting midlevel staff with highly researched social engineering.
NEWS
The Phantom Deal campaign involves threat actors conducting extensive reconnaissance on large enterprises to fabricate merger and acquisition scenarios. These actors specifically target midlevel employees with the authority to initiate wire transfers, using detailed company knowledge to lend credibility to their fraudulent requests.
Why I Care
This matters because financial losses from these scams can be massive, and traditional email filters often miss highly personalized social engineering attacks that exploit internal trust and urgency. Midlevel staff are increasingly becoming the primary attack vector for high-value fraud.
Next Steps
Finance and HR teams should immediately reinforce verification protocols for all external transfer requests, while security leaders must implement mandatory training on M&A scam indicators for employees with payment authority by the end of this quarter.
Source: Dark Reading ·