# Phantom Deal: When the NDA Is the Payload

## Summary

It started with an innocuous WhatsApp message:

> *"Hi David, I hope you are well. Are you at the office?"*

The sender claimed to be a real Gen executive based in Dublin. The profile used his name, his photograph and an Irish telephone number. The opening message **mentioned no money, no urgency and no acquisition**. It was designed purely to establish whether the recipient was available and willing to respond.

It ended with a request to transfer **€626,735.45** to a company in Hong Kong.

Between those two points sat a forged NDA branded as a PwC document. And that is the most important thing about this campaign: **the NDA was not supporting material for the story. It was the payload.**

Gen Digital calls the campaign **Phantom Deal**, published on 2 September 2026. Following the trail from the document, they found **four additional individuals** who had received closely related NDAs — different companies, advisers and acquisition narratives, but remarkably consistent structure, communication rules and document fingerprints.

What makes this worth writing up for a SOC audience: **there was no malware, no malicious attachment, no compromised corporate mailbox.** Gen states it plainly — a security team searching only for malware or suspicious email links **would miss the entire operation**.

**Priority action: review whether your payment approval process allows anyone — including the CEO or a board member — to bypass verification on grounds of transaction confidentiality.**

* * *

## Why the NDA Is the Payload

Fake legal documents are common in corporate fraud. But in Phantom Deal the NDA served a far more important role than simply making the acquisition story look credible.

**It established the rules under which the victim was expected to operate.**

The document introduced a confidential acquisition, imposed a strict disclosure regime, set a near-term date for the supposed public announcement — and most importantly, **required communication to take place through WhatsApp and personal email**.

Read that again.

Under normal circumstances, an instruction to avoid company systems and exclude colleagues from a major transaction is a warning sign obvious enough that no training is needed to spot it. **Inside the fiction created by the NDA, the same behaviour could be presented as a legal obligation.**

Gen describes the intent precisely: the attackers were attempting to **turn the company's own confidentiality culture against it**.

The target was encouraged not to involve colleagues, not to discuss the transaction through normal channels, and not to verify the instructions with Legal, Finance, Treasury, Compliance or Corporate Development. A recipient who treated the NDA as genuine would become **increasingly isolated from exactly the colleagues most likely to challenge the story**.

That is why Gen titled the report as it did, and the title earns its place: the NDA was not an accessory to the attack. It was the payload.

* * *

## The Attack Chain

1.  **An opening WhatsApp message** from the first impersonated identity — a real internal executive, with the correct photograph, name and a phone number using the right country code.
    
2.  **The first phone call — and the break point.** David worked in Gen's legal team and knew the colleague being impersonated. The unfamiliar number raised suspicion; the call confirmed it: **the voice did not match**.
    
3.  **A second impersonated identity appears.** This time the attacker impersonated a genuine professional associated with PwC, and **asked the target to provide a private email address**. Gen emphasises that this request was not incidental.
    
4.  **The forged PwC-branded NDA** arrives, imposing confidentiality and forcing the communication channel as described above. The victim was told the transaction would become public on **19 June 2026** — the NDA had been presented only days earlier. That short window created pressure while providing a ready-made explanation for why the matter could not be discussed more broadly.
    
5.  **The payment instructions.** The supposed adviser asked **Avast Software s.r.o. to transfer money on behalf of NortonLifeLock Ireland Limited**. The amount was precise: **€626,735.45**. The beneficiary was a company in Hong Kong, the payment described as an **"Advance Retainer for Professional Services"**, and the document stated the amount would be recorded as an intercompany receivable and reimbursed when the acquisition was formally announced.
    
6.  **Follow-up and proof demands.** The attacker repeatedly pressed for confirmation the transfer had completed, demanding a **SWIFT MT103**, and then additionally a **UETR number**.
    

### The Story Was Built on Real History

The attackers had studied Gen's history. The acquisition narrative referenced **Avast Software and NortonLifeLock Ireland Limited**, drawing on the real acquisition of Avast by NortonLifeLock in 2022 and the subsequent creation of Gen Digital.

The names were familiar, the corporate relationship had genuinely existed, and an intercompany transaction could appear entirely plausible to someone operating under pressure and secrecy.

This was not a generic message sent to thousands of employees. **The story had been adapted to its target.**

But while the targeting was tailored, the execution was not flawless. David quickly identified inconsistencies in the explanation for why Avast should make a payment on behalf of NortonLifeLock Ireland Limited. His legal background and familiarity with internal transaction processes made those gaps easier to spot.

Gen's conclusion on this point is candid, and it is the part that should worry you: **a more coherent payment narrative could have made the same playbook considerably more convincing.**

* * *

## MT103 and UETR: The Most Operationally Valuable Detail

Once the payment instructions had been delivered, the tone changed.

The attacker began following up for confirmation that the transfer had been completed. The target was asked to provide a **SWIFT MT103** — the banking message used as evidence that an international transfer has been executed.

> *"I need a swift MT103, it's an official proof of wire transfer to attached to the package."*

Later, after receiving what appeared to be a confirmation email, the attacker complained that the link would not open and asked for the document as a PDF. He then added another requirement: the confirmation should contain the **UETR number** — a unique reference used to track a payment through the SWIFT network.

Gen's analysis of what these two requests mean is exactly right: they **confirmed the objective**. The attackers wanted proof that the funds were moving, **and the information needed to monitor the transfer — potentially reducing the time available for the company or its bank to intervene**.

This is the detail I consider most actionable in the whole report, and Gen puts it directly into its recommendations: **staff involved in payments should be trained to recognise requests for MT103 documents, UETR references and other confirmation data as part of the fraud chain, not merely as administrative follow-up.**

In most awareness programmes today, the "after the money has moved" stage is not covered at all. Yet that is exactly the stage where the attacker needs the most cooperation — and the last stage at which the organisation still has a chance to notice and call the bank.

* * *

## The Counter-Move: Canary Tokens and How to Read the Data

Once David had identified the scam, the objective shifted from verification to intelligence gathering. Working with Gen's researchers, he continued the exchange while the team controlled the material being sent and monitored how the operation responded.

They prepared two things:

*   A **fake account statement**, showing what appeared to be the requested payment and the remaining company balance. The document contained a **hidden marker** that could identify whether it was opened on a system protected by one of Gen's products.
    
*   A **fake Citibank-style confirmation email**, containing the transaction amount, beneficiary and payment reference the criminals expected, together with a link to view the full transaction details. That link did not lead to real banking information — it contained a **canary token** allowing the researchers to record when it was opened. When the attacker reported the link was not working, the team suggested his VPN might be causing the problem and asked him to disable it. Further access attempts followed within minutes.
    

### The Number, and How to Read It Correctly

The token recorded **49 HTTP requests from 43 IP addresses over 24 days**.

This is where I want to pause, because how Gen presents this figure is a lesson for anyone working with canary tokens.

Gen says so immediately: most of the activity in the first minutes came from **automated scanners, cloud services and redirect-analysis systems**, so **the raw count does not represent 49 actions by the attacker**.

After filtering that noise, the remaining data showed repeated interaction through VPNs, proxy services and several non-hosting internet connections. Some visits were separated by hours or days and used different browser profiles — behaviour consistent with a person returning to the link and attempting to retrieve the promised payment information.

And Gen states the limits directly: the network data helped separate scanner traffic, proxy infrastructure and repeated manual access, **but it was not enough to attribute the operation**. Some later visits came from ordinary ISP ranges, but those connections **show where the traffic exited, not necessarily where the fraudsters were located**.

The most cautious conclusion the data supports: there was repeated manual access by someone connected to the fraud operation, **including long after the supposed transfer should have been completed**.

* * *

## From One Attack to a Wider Campaign

The controlled interaction gave Gen visibility into the live fraud attempt. But the forged NDA gave them something else: **a set of document fingerprints to hunt with**.

Using its structure, wording and embedded identifiers, the team found **four additional NDA samples** connected to other targeted individuals.

**The victims spanned very different sectors:** senior people in private equity, industrial finance, sales, mining and energy. For each of them, an acquisition or strategic investment narrative would have been credible enough to justify initial engagement.

**The adviser branding also changed:** some documents impersonated **PwC**, while others used **KPMG** or **Ogier** branding. Gen states the necessary caveat clearly: **there is no indication that any of these firms were compromised or involved in the operation.** Their names and identities were being abused to make the documents appear legitimate.

Despite the different branding, the documents **followed substantially the same sequence of sections and reused the same legal language**. They all imposed confidentiality, directed communications towards WhatsApp and personal email, and introduced a short period between the NDA date and the supposed public announcement.

They also contained **the same unusual numeric identifier** across documents attributed to different firms and prepared for unrelated recipients. Gen explains this is common residue when criminals reuse document templates: names, dates, logos and transaction references may be changed, while **less visible elements remain untouched**.

The repeated structure suggests the attackers **were not building each operation from scratch**. They had developed a **reusable M&A fraud package** that could be adapted to different people and companies.

### The Limits, Preserved

Gen is very clear about the boundaries of its evidence, and this is worth learning from when writing internal reports:

In the Gen case, they observed **the complete chain** — from WhatsApp contact to payment request and demand for MT103 confirmation. For the other four targets, they found the malicious NDA documents carrying the same core narrative and document fingerprints, **but did not observe the later payment stage**.

Taken together, the evidence points to a wider M&A-themed fraud campaign built around the same narrative and document toolkit. But it **does not establish that every target received identical payment instructions or that every document was operated by the same individual**.

### The Irony at the End

Gen closes with an observation worth preserving.

After spending days building a narrative around trust, secrecy and urgency, someone connected to the fraud operation **repeatedly interacted with the fake payment confirmation the Gen team placed in front of them**.

And at a deeper level: the NDA was intended to keep the operation confidential. **Its reused language, structure and identifiers ultimately helped expose the campaign behind it.**

* * *

## What Saved Gen

Luis Corrons, Security Evangelist at Gen and co-author of the report, identifies two things David did right:

**First, he verified the person rather than trusting the identity presented on the screen.** The unfamiliar number raised suspicion; the call confirmed it.

**Second, he understood what a legitimate transaction should look like.** That let him recognise the payment explanation made no sense, despite the carefully built story around it.

And this is the line worth putting directly into training material:

> **Don't just ask whether the person looks legitimate. Ask whether the process they are asking you to follow is legitimate.**

Alongside that is a practical point Corrons makes explicitly, and one easy to misread: for most employees, **once they suspect something, the correct next step is to report it, not to continue engaging with the scammer**. Playing along in this case was a controlled decision by a security research team, not behaviour to encourage in ordinary staff.

Corrons adds something worth building into organisational culture: even if you report it and it turns out to be a legitimate transaction, **your company will appreciate that you are being safe**.

* * *

## Assessment

**This is an attack on process, not on a technical vulnerability.**

Gen states this directly, and it is the sentence that matters most to a SOC: the attack was designed to **induce a process failure rather than exploit a technical vulnerability**. The criminals attempted to convince the target that bypassing normal controls was **necessary to protect a confidential deal**.

The consequence is concrete: there is nothing for existing tooling to detect. No hash to block, no domain to blocklist, no attachment to sandbox, no anomalous login to alert on. The campaign never travelled through company systems — **that was the entire purpose of the NDA**.

**The warning signs appeared much earlier than the Hong Kong bank account.** Gen puts it succinctly: keeping a sensitive corporate transaction on WhatsApp and personal email **was already enough to require independent verification**. You did not need to wait for an amount and an account number.

**On the security-through-obscurity paradox.** Corrons rejects the instinctive response of removing information from the internet. The attackers used names, photographs, job roles and acquisition history, **most of which is legitimately public and, in many cases, needs to be public**.

His alternative framing belongs in strategy discussions: **assume criminals can learn a great deal about your organisation. The defence has to be that even somebody who has done excellent reconnaissance still cannot talk an employee into bypassing verification and payment controls.**

**M&A as a two-directional attack surface.** Phantom Deal *fabricated* a deal. But real M&A carries risk in the other direction: when one company acquires another, it does not just inherit assets and people — it **absorbs an entire digital footprint**, including endpoints, credentials, legacy systems and in many cases lurking vulnerabilities or an undetected compromise. Both risks share the same enabling condition: **the culture of secrecy surrounding M&A**, which limits both who knows and who is able to ask questions.

**And a note on where this sits in the history of fraud.** Advance-fee fraud is the oldest gambit in the book. There is a well-known argument from a Microsoft researcher that the obviousness of the "Nigerian Prince" scam is **deliberate**: by sending an email that repels all but the most gullible, the scammer gets the most promising marks to self-select and tilts the true-to-false-positive ratio in his favour.

Phantom Deal **inverts that logic entirely**. It does not filter — it targets one specific person, with a story tailored to real corporate history. Corrons summarises the consequence: *"Scams are becoming so convincing that even the most trained eye can have trouble spotting them."*

Twenty years ago, bad grammar was the filter. It no longer is.

### Relevance for Vietnam

**The most important point here is that one of Gen's rules does not transfer cleanly to Vietnam.**

Gen recommends that *"changes of communication channel, especially from corporate systems to private accounts, should trigger additional scrutiny."* In a European context this is a strong signal — moving an important business discussion to personal WhatsApp is unusual.

**In Vietnam it is not.** Moving work discussions to personal Zalo is entirely normal, including with executives, including for important matters, including in organisations with fully provisioned corporate email and chat. The signal is **saturated to the point of losing its warning value**.

The practical consequence: applying Gen's rule as written would either be ignored for generating too many false positives, or never applied at all. **The focus has to shift to a different control point** — not the communication channel but the payment request. A rule better suited to the domestic context: every payment instruction, regardless of the channel it arrived through or who it came from, **must be verified through an independently established communication channel** — a phone number from the internal directory, not one appearing in the conversation itself.

**Hierarchical culture raises the risk.** Gen stresses that the rules must apply equally when the request appears to come from the CEO, a board member or someone already known to the recipient. In Vietnamese corporate environments, a mid-level employee challenging a request from senior leadership requires noticeably more courage than in many other cultures. **If the process does not protect the person asking the question, nobody will ask it.**

**Subsidiary structures are a highly logical target.** Phantom Deal exploited exactly the pattern of "company A pays on behalf of company B within the same group" — and that is precisely the structure of a great many foreign-parent subsidiaries operating in Vietnam. In those organisations, intercompany transactions are routine, the approver in Vietnam often lacks full context on the parent company's affairs, and "headquarters requested it" is a justification rarely challenged.

Add to that the growing volume of M&A activity in Vietnam, which means **the background narrative Phantom Deal relies on is becoming more credible, not less**.

* * *

## Recommendations

*   **Payment instructions must be verified through an independently established channel**, not through contact details supplied during the transaction — this is the single most important rule and it does not depend on which channel is in use.
    
*   **No executive, adviser or board member should be able to override payment controls** through WhatsApp, Zalo, personal email or a confidentiality claim — and the process must protect the person asking the question.
    
*   **Train payment staff to recognise MT103 and UETR requests as part of the fraud chain**, not as routine administrative follow-up — this stage is missing from most awareness programmes today.
    
*   **Establish a defined escalation route for Legal, Finance, Treasury and Corporate Development** for unexpected transaction requests, and make clear that reporting a transaction that turns out to be legitimate is recognised behaviour, not a mistake.
    
*   **Contact external advisers using verified directory information** whenever their identity or instructions are in doubt — never using a phone number or email that appeared in the conversation.
    
*   **For foreign-parent subsidiaries:** require two-way confirmation for any unusual intercompany transaction, through group channels rather than individual contacts — this is exactly the structure this campaign targeted.
    

* * *

## References

*   Gen Digital — [The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign](https://www.gendigital.com/blog/insights/research/phantom-deal), Martin Chlumecký and Luis Corrons (2 September 2026) — original report
    
*   Dark Reading — [Large Enterprises Targeted in Fake Merger & Acquisition Scams](https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams), Nate Nelson (3 September 2026)
    
*   Dark Reading — [The Hidden Cybersecurity Risks of M&A](https://www.darkreading.com/cyber-risk/hidden-cybersecurity-risks-mergers-acquisitions), Denny LeCompte — inherited risk in real M&A
    
*   Dark Reading — [Will Generative AI Kill the Nigerian Prince Scam?](https://www.darkreading.com/cybersecurity-operations/will-generative-ai-kill-nigerian-prince-scam), Nate Nelson — background on advance-fee fraud and the "bad grammar is the filter" argument
    
*   Microsoft Research — [Why do Nigerian Scammers Say They are from Nigeria?](https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/WhyFromNigeria.pdf) — the original research on victim self-selection
