Phantom Deal Targets Staff Who Can Move Money

Gen said the Phantom Deal campaign tried to trick at least five large enterprises, including the company behind Norton and Avast, into sending large transfers under the cover of fake merger-and-acquisition talks. The attackers did not go after a CEO inbox; they worked the people who handle deal-adjacent tasks and payment requests. The ruse used real company history and plausible executive impersonation to make the transfer request sound like normal corporate work. In Gen’s case, the story leaned on the NortonLifeLock and Avast acquisition history, which gave the payment a believable business reason even though the deal story did not fully hang together. For enterprises that let email, chat, or phone requests start wire payments, the exposure sits in the approval workflow itself. If staff with transfer authority can be reached with a convincing deal pretext, the fraud can land as a business process failure rather than a mailbox compromise.

Part of the PlainSec briefing for 2026-09-04

Editions

Sources