News and updates from Maple

The fake acquisition scam finance teams need to know about right now image

The fake acquisition scam finance teams need to know about right now

A fraud campaign making headlines this week is worth flagging directly, because it's built specifically to catch the kind of people who read this blog: private equity professionals, finance leaders, and anyone involved in deal work.

What's happening

Security researchers this week detailed a campaign dubbed "Phantom Deal Fraud", in which attackers impersonate executives and convince targets, often in legal or finance teams, to move a conversation onto WhatsApp or a personal email address, then push through an international wire transfer using forged acquisition documents. The pitch is a tightly controlled, confidential deal: a merger or investment opportunity, coordinated by a supposedly reputable adviser, with a small group involved and an announcement approaching fast.

What makes it effective is how convincing the paperwork looks. The forged documents follow the same structure and legal language real acquisition documents use, and targets have included senior people in private equity, industrial finance, mining and energy. The confidentiality request and the shift to personal channels both serve the same purpose: getting the target away from the email security, verification habits, and colleagues that might otherwise catch the scam.

Why this lands differently for our clients specifically

This isn't a generic phishing email hoping someone clicks a link. It's built around exactly the scenario a hedge fund, family office or PE-adjacent firm actually finds plausible: a confidential deal moving fast, introduced through what looks like a legitimate channel. The entire pitch is designed to feel like normal deal flow, right up until the wire transfer instruction.

A second, related warning this week

Separately, the UK's National Cyber Security Centre published a warning about "Shadow AI", the unapproved AI tools employees use without a business knowing. Their point is a straightforward one: information typed into a personal AI account can leave a firm's control entirely, and the tools themselves can carry vulnerabilities that expose whatever data they're connected to. It's a reminder that this week's theme (AI-era scams) cuts both ways. It's not just about attackers using AI against you, it's also about what your own team might unknowingly be handing an AI tool nobody's approved.

What to actually do about both

  • Treat "move this to WhatsApp or a personal email" as a red flag in itself, regardless of how legitimate the deal sounds. Confidential deals still go through proper channels.
  • Verify any new counterparty, adviser or deal introduction through an independent channel you already trust, not a phone number or email provided within the deal documents themselves.
  • Apply the same out-of-band verification to any wire instruction, no exceptions for time pressure or confidentiality requests, both of which are deliberately part of the manipulation.
  • If you don't already have a clear answer on which AI tools are approved for use with client or deal information, that's worth resolving before the next Shadow AI incident, not after.

We'll keep flagging campaigns like this as they surface. If a deal introduction has landed that ticks any of the boxes above, it's worth a second look before it's a wire transfer.