Knowbe4 iconKnowbe4Sep 14, 2026 ~4 min source read

Phony NDAs Used to Push Targets off Corporate Channels in Sophisticated Social Engineering Campaign

Researchers tracking the campaign found attackers used forged non-disclosure agreements and realistic acquisition narratives to move conversations to WhatsApp and personal email, isolating employees before attempting a payment request. The target in this case recognized inconsistencies and avoided loss.

Social Engineering Campaign Uses Phony NDAs to Avoid Detection

Share this story

Send the public story page.

Useful takeaways from this story.

Attackers used forged NDAs that explicitly instructed victims to handle the matter over WhatsApp and personal email to avoid corporate detection.

The campaign combined impersonation of real executives and consultants with a believable acquisition story tied to Avast and NortonLifeLock/Gen Digital.

# What happened

# How the attack was structured The operation began with impersonation of a real Gen executive based in Dublin. That persona introduced a second impersonated individual who claimed to work at PwC. After initial trust-building, the attackers asked the target for a private email address. The forged NDA that followed explicitly instructed the recipient to keep all acquisition-related communication on WhatsApp and personal email.

The narrative behind the approach drew on actual corporate history. The fabricated acquisition referenced Avast Software and NortonLifeLock Ireland Limited and connected those names to the creation of Gen Digital. That choice made the storyline familiar and potentially plausible to a company insider.

# Why the attackers wanted private channels By moving the conversation off corporate systems, the threat actors attempted to bypass internal monitoring, gatekeepers, and standard transaction controls. The campaign kept details and any payment instructions out of channels where security teams and automated systems would normally detect anomalies.

The targeted employee recognized red flags and intentionally engaged with the attackers to observe their behavior. Because the employee had legal experience and knowledge of internal transaction processes, they identified inconsistencies in the explanation for why Avast should make a payment on behalf of NortonLifeLock Ireland Limited. Those inconsistencies undermined the payment story before money was requested or transferred.

# Assessment of the attackers' capability This was a tailored operation rather than a broad spray campaign. The threat actors performed reconnaissance to reference real corporate events and relationships, making the story more credible. However, execution had gaps: the payment narrative and some transactional details were inconsistent. Had those details been tighter, the same playbook could have been considerably more convincing.

# Concrete signals to watch for

  • Requests to move an official matter to WhatsApp or a personal email address, especially when accompanied by a formal-looking document such as an NDA.
  • Introductions that involve impersonation of internal executives plus a second party claiming to be a trusted external advisor or consultancy.
  • Narratives that reference real past transactions or acquisitions that make the scenario appear familiar.

# Bottom line The campaign demonstrates a repeatable social engineering approach: use believable context and forged documents to isolate a target on channels outside corporate controls, then present a payment request. In this incident the target's background and vigilance prevented loss, but the tactic is credible enough that small inconsistencies are the difference between detection and compromise.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app