logo

Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers

ID: b6826ac1-58d2-50da-87b2-7e4da5b4920b

STIX ID: report--b6826ac1-58d2-50da-87b2-7e4da5b4920b

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-09-03

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

Gen Digital analysts identified a targeted social‑engineering campaign called "Phantom Deal" that uses WhatsApp impersonation and fake, PwC‑branded NDAs to steer employees into making large cross‑border wire transfers while avoiding official corporate channels; the attack involved no malware or mailbox compromise but exploited business processes and could result in significant financial loss if payment instructions are trusted without independent verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.