Threat actors impersonated Gen executives and major consulting firms in a targeted business email compromise-style operation that used forged non-disclosure agreements to isolate a legal employee and pressure the company into transferring €626,735.45 to a Hong Kong entity.
Dubbed Phantom Deal, the campaign shows how financially motivated actors can abuse legitimate M&A processes, corporate history and confidentiality requirements without deploying malware, exploiting software flaws or compromising an email account.
The objective was not to defeat endpoint security, but to convince an employee to bypass the internal controls designed to stop fraudulent payments.
The profile used the executive’s real name, photograph and an Irish phone number. Initially, it made no reference to money, acquisitions or urgency.
The recipient, identified by Gen as “David,” worked on the company’s legal team and personally knew the executive being impersonated.
An unfamiliar number triggered suspicion, while a follow-up phone call confirmed that the caller’s voice did not match the real employee.
After the initial contact, the operators introduced a second fake identity: a purported PwC professional.
The impersonator asked David to move the conversation to a personal email address, setting up the next and most important stage of the operation the delivery of a forged NDA.
The fraudulent PwC-branded NDA presented a confidential acquisition and imposed strict secrecy provisions.
It directed the target to use WhatsApp and private email rather than corporate communications, while discouraging discussion with colleagues in Legal, Finance, Treasury, Compliance or Corporate Development.
That instruction was central to the scam. By framing isolation as a contractual obligation, the actors attempted to turn normal corporate confidentiality practices into a mechanism for suppressing independent verification.
The fake acquisition narrative also exploited real corporate history. It referenced Avast Software and NortonLifeLock Ireland Limited, entities linked through NortonLifeLock’s 2022 acquisition of Avast and the formation of Gen Digital.
This gave the proposal enough contextual credibility to make an intercompany payment appear plausible.

Gen Researchers said that, the campaign began with an apparently routine WhatsApp message from an attacker posing as a genuine Gen executive based in Dublin.
Fake Acquisition Scam
David identified inconsistencies in the claim that Avast Software s.r.o. should make a payment on behalf of NortonLifeLock Ireland Limited.
His knowledge of internal legal and transaction processes prevented the attackers from advancing the payment fraud.
The fake adviser later instructed Avast Software s.r.o. to transfer €626,735.45 to a company in Hong Kong.
The payment was labeled an “Advance Retainer for Professional Services” and was falsely described as an intercompany receivable that would be reimbursed after the public announcement of the acquisition.
The fraudsters added urgency by claiming the transaction would be announced on June 19, 2026. They then repeatedly requested a SWIFT MT103, the payment message used as proof that an international wire transfer has been executed.
The actor also asked for the payment’s UETR, or Unique End-to-End Transaction Reference, which can be used to track a transfer across the SWIFT network.
Those requests indicated that the attackers wanted confirmation that funds were in motion and enough data to monitor the payment before a bank or corporate treasury team could intervene.
Once Gen identified the fraud attempt, its researchers continued the interaction in a controlled manner. The team supplied a fake account statement and a fake Citibank-style payment-confirmation email containing a tracked link protected with a canary token.
The token logged 49 HTTP requests from 43 IP addresses over 24 days. Gen said much of the initial activity came from automated scanners, cloud services and redirect-analysis infrastructure.

After filtering the noise, researchers identified repeated access through VPNs, proxies and non-hosting ISP connections, consistent with manual interaction by someone involved in the fraud operation.
The telemetry was insufficient for attribution, but it demonstrated continued interest in the purported payment confirmation.
Gen subsequently identified four additional targets that had received related NDA documents. Those victims included senior personnel in private equity, industrial finance, sales, mining and energy.
While the forged documents used different narratives and impersonated advisers including PwC, KPMG and Ogier, they retained similar section ordering, legal language, secrecy requirements and unusual numeric identifiers.
Gen said there is no evidence the named advisory firms were compromised or involved.
The campaign illustrates a growing risk for legal, finance and M&A teams: an NDA can legitimately restrict information sharing, but it must never prevent authentication of payment instructions.
Any deal that shifts communications to WhatsApp or personal email, demands exceptional secrecy, or requests MT103 and UETR data should trigger independent verification through trusted corporate contacts and established banking controls.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.





