Threat Intelligence

‘Phantom Deal’ Scam Uses Fake Mergers to Trick Employees Into Wire Transfers

Dark Reading · 4 Sept 2026
Key Takeaway Require independent verification—through a known phone number or in-person confirmation—before approving any unexpected large financial transfer, even if the request appears to come from a legitimate business deal.

A newly identified scam campaign, dubbed 'Phantom Deal,' is targeting large enterprises by impersonating merger and acquisition activity. According to researchers, the threat actors behind the campaign conduct extensive research into their target companies, building convincing scenarios designed to deceive employees.

The scam specifically aims at midlevel employees—those often trusted with initiating or approving financial transactions but who may lack full visibility into a company's broader deal-making activity. By posing as legitimate M&A processes, attackers attempt to pressure staff into authorising large wire transfers under the guise of completing a business transaction.

While this campaign has so far focused on large enterprises, the underlying tactic—detailed research combined with a plausible, high-pressure financial scenario—is a technique that can just as easily be adapted to target small and medium businesses, particularly those involved in supplier relationships, investment discussions, or business sales.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.