220175857203
academy
Security
Privacy
Performance
English

Phantom Deal: Inside an Imposter Scam Targeting an Avast Employee

When scammers singled out an Avast employee in a sophisticated social engineering attack, they picked the wrong target — and revealed more about themselves than they ever came close to stealing. Threat Researchers at Gen, the company behind Avast, played along with the scammers, analyzing their moves to gather intelligence. Our Threat Researchers dubbed this imposter scam “Phantom Deal” in their technical analysis. The scheme involved executive impersonation, forged legal documents, and off-channel communication, all wrapped around a hush-hush acquisition requiring a large money transfer. Find out what we learned.

academy-phantom-deal-hero
Written by Luis Corrons
Reviewed by

Published on September 3, 2026
This Article Contains
This Article Contains

    Key takeaways

    • Phantom Deal is a targeted M&A-style imposter scam built around real names, real company history, and a fake NDA.

    • The scam works by isolating the target, moving them off normal channels, and pushing an urgent wire request.

    • Our Threat Researchers have found the same template and document fingerprints in four other targets across several industries.

    Anatomy of Phantom Deal

    Phantom Deal is an imposter scam campaign that uses a corporate acquisition involving an NDA as a pretext to trick an employee into making a large payment.

    The scam relies heavily on social engineering — an attempt to psychologically manipulate a victim into revealing confidential information or doing something they shouldn’t. It draws on other scam tactics, too: spear phishing, off-channel communication, and the aura of secrecy surrounding NDAs were all important elements in this scheme.

    Read on for a breakdown of how this scam went down, and what we learned about the Phantom Deal campaign.

    Illustration of how Phantom Deal scams play out.

    1. An Avast employee gets a call from a “trusted coworker”

    It all began with a WhatsApp message from someone claiming to be a Dublin-based executive at Gen (the company behind Avast) to an employee we’ll call David.

    The message, which featured the name, photo, and Irish country code of a real Gen executive we’ll call Edwin, seemed innocent at first. There was no contrived urgency or suspicious spelling and grammar — typical signs of a scam. Just “Hi David, I hope you are well.”

    Screenshot of a WhatsApp message from an imposter executive

    But then the phone call came.

    The scammer had copied the executive’s identity, but, crucially, not his voice. David knew the executive personally and immediately realized the caller was an impostor.

    Instead of just hanging up, he played along, got in touch with our Threat Researchers, and flipped the script from target to investigator.

    “Edwin” laid out the situation. A major acquisition was in the works, and secrecy was essential.

    2. A “consultant” enters the picture

    Next, a second character introduced himself. Philippe was a supposed PwC consultant attached to the confidential deal.

    Once again, the scammers had borrowed the identity of a real person, so a quick Google search of the consultant’s name and position wouldn’t necessarily have raised red flags.

    Screenshot of a WhatsApp message from an imposter PwC consultant.The “consultant” asked David to use a personal email address, explaining that the sensitive nature of the deal required them to move communications off-channel.

    For the scammers, this was a key moment. Switching to an unmonitored environment allowed them to bypass normal oversight, meaning fewer opportunities for someone in Legal, Finance, or Corporate Development to spot something was wrong.

    3. An NDA defines the rules of engagement

    The scammers followed up with a polished fake NDA carrying PwC branding. Besides serving as window dressing for an already convincing scam, the NDA defined the rules of engagement: secrecy was legally binding.

    In convincing legal language, the document spelled out who could know about the details of the deal and when it would be made public. Discussing the acquisition outside that small circle — or via official company channels — was strictly prohibited.

    4. The scammers request a money transfer and proof that it was sent

    Once the fake deal was in place, the scammers made their move. They instructed David to send €626,735.45 (over $722,000 at the time of writing) to a company in Hong Kong for what they described as an advance retainer for professional services.

    And they wanted receipts.

    The scammers repeatedly requested a SWIFT MT103, formal proof that an international transfer had been executed, as well as the UETR number used to track the payment through the SWIFT network.

    WhatsApp screenshots of an imposter PwC consultant requesting receipts for a money transfer.

    What our threat researchers did next

    The request for official documentation provided an opportunity for our Threat Researchers. To learn more about the scammers, they prepared a fake account statement showing the requested payment, then sent a fake bank confirmation email with a trackable link to the supposed transaction details. That link contained a canary token, which is a decoy URL that records when someone opens it.

    Our Threat Researchers even persuaded the scammers to turn off their virtual private network (VPN) after they complained that the link would not open. Further access attempts followed within minutes, giving our team additional network fingerprints, although this was not enough information to determine the attackers’ true location.

    The token hidden in the link gave our researchers a controlled way to observe how the scammers interacted with it, without sending any real money or banking information.

    Screenshot of a fake transaction confirmation from Citibank.

    What we learned about this scam scheme

    After filtering out traffic noise, analysis of requests to the fake link confirmed what our Threat Researchers already suspected. Repeated visits were consistent with a human checking over and over to see whether the six-figure transfer had arrived.

    Our Threat Researchers weren’t able to identify where exactly the fraudsters were located, but they were still able to gather important information. Details of the forged NDA pointed them to other individuals targeted by the Phantom Deal scam and allowed them to draw important conclusions.

    Phantom Deal is a broad campaign

    Our Threat Researchers’ investigation linked the forged NDA to four other targets across several industries, including energy, industrial finance, mining, private equity, and sales. The names, companies, advisers, and transaction details changed (some referenced KPMG or Ogier instead of PwC), but the documents kept the same structure, legal language, and other identifiers. That points to a reusable fraud template and a broader scam campaign.

    Phantom Deal scams are highly personalized

    The attackers spent time researching real executives, advisers, company history, and believable business relationships to make the story feel credible. This makes Phantom Deal scams similar to spear phishing, where phishers target specific individuals. In the Avast case, they even drew on the genuine acquisition history linking Avast, NortonLifeLock, and Gen.

    Technical exploits aren’t required

    Phantom Deal scammers don’t need to be hackers, nor do they need to steal login credentials or install malware . Instead, their goal is to manipulate their target into breaking normal procedure. They use authority, secrecy, urgency, and familiarity to make risky behavior feel mandatory, a hallmark of social engineering.

    Why targeted scams like Phantom Deal are so dangerous

    Scams like Phantom Deal are effective because cybercriminals invest time researching their targets, which helps them craft more convincing pretexts. They may be familiar with details you wouldn’t expect.

    In Phantom Deal, the attackers impersonated known executives and advisers, referenced genuine corporate history, and used forged legal documents to make the request appear legitimate. These familiar details can lower a target’s guard and make an unusual request seem plausible.

    Likewise, claims of confidentiality and urgency can pressure employees to avoid colleagues, move conversations to personal accounts, and bypass established controls. By the time money is requested, the target may already feel committed to protecting a supposedly sensitive transaction.

    An NDA can limit who is told about a transaction. It should never prevent the transaction from being authenticated. Changes of communication channel, especially from corporate systems to private accounts, should trigger additional scrutiny. — Luis Corrons, Security Evangelist at Avast

    How to avoid falling for a Phantom Deal scam and wiring six figures into the void

    Imposter scams cost U.S. consumers over $3.5 billion in 2025, according to FTC data. To avoid becoming another statistic, here are some practical ways to reduce your exposure.

    • Verify unexpected requests: NDAs may limit what can be shared, but they should never prevent you from using official channels to confirm requests.

    • Escalate anything unusual: Don’t be afraid to loop in Legal, Finance, Security, or your direct manager if something feels off.

    • Keep communications on official platforms: Treat a request to move a deal to WhatsApp or personal email as a red flag.

    • Never bypass normal controls: Urgency or confidentiality are not reasons to skip approval steps. Use the company’s established payment and escalation channels, even for sensitive transactions.

    • Use cybersecurity software: As a consumer, you can install dedicated antivirus software, like Avast One, to help alert you to scams and protect you from malware.

    More Security Articles

    Phantom Deal: Inside an Imposter Scam Targeting an Avast Employee

    What Is UPnP?

    Why is My iPhone in SOS Mode?

    New Avast One vs Legacy Avast One: What’s Changed?

    What Is the New Avast One?

    Is Mercari legit? A guide to safe shopping and avoiding scams

    Is WeTransfer Safe?

    Is Poshmark Legit?

    Is WhatsApp Safe?

    Is Apple Pay Safe?

    How to Bypass Apple Activation Lock (and Which Methods to Avoid)

    Is Windows 10 Still Supported? It Is by Avast

    Security Tips
    Security
    Luis Corrons
    3-09-2026