€10M Deal Hid a Power of Attorney Trap

Hacker Noon Cybersecurity · Medium sophistication
Last updated August 5, 2026

A foreign investor signed transaction documents for a €10M land purchase after being told one document would “protect the company.” The document instead granted broad power of attorney and sale-like authority, and the investor discovered the issue only 18 months later when the local lawyer stopped responding. The case highlights how over-reliance on a single adviser and lack of independent review can quietly transfer control.

Key findings

  • A document presented as protective actually “functioned as a power of attorney combined with a sale authorization,” granting broader authority than the investor understood.
  • The investment’s governance depended on “almost entirely on one professional relationship,” with no independent legal review and no secondary adviser receiving executed copies.
  • The problem went undetected for “eighteen months,” until the investor reviewed the investment and the lawyer “stopped responding.”
  • Once broad authority was delegated, “recovering control became considerably more difficult than acquiring the asset.”

Who’s being targeted

  • Commonly targeted roles: Executives, Business owners/founders, Finance teams, Legal/Compliance, Investment/Corporate development.
  • Affected industries: Investment management / asset management, Cross-border real estate investment, Professional services (legal, fiduciary).
  • Attack channels: physical.
  • Impersonated: Local counsel / trusted fiduciary (as the investor’s adviser).

Awareness takeaways

  • Never sign authority-granting documents (power of attorney, sale authorization, signing authority) without independent review focused only on your interests.
  • Avoid single points of failure: ensure executed documents and key reporting go to more than one trusted party.
  • Treat delegated authority as something to monitor over time, not a one-time closing task.
  • Assume relationships can change and design governance so control cannot be quietly concentrated elsewhere.

Red flags to watch for

  • A document described as protective but it “granted far broader authority than he understood”
  • No independent review before signing and no second adviser receives executed copies
  • Single adviser controls preparation, explanation, custody of signed documents, and ongoing local communications
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine a €10 million deal… and one extra document you’re told will “protect the company.” In this real case, that “protective” paper actually functioned as a power of attorney plus sale authorization, giving someone else legal power to act, even sell, on the investor’s behalf. Here’s the scary part: the entire €10M investment relied almost entirely on one local adviser. No independent legal review, no second adviser copied on the signed set, and for eighteen months, no one noticed how much control had been handed away. Your move: if any document grants power of attorney, signing authority, or sale authorization, pause and send it for truly independent review, someone whose only job is to protect your side.

MITRE ATT&CK techniques

Similar attacks

AI Vishing Works Because Scripts Persuade

AI Vishing Works Because Scripts Persuade

Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds perfectly human. Even when listeners correctly suspect the voice is synthetic, many still continue the conversation and may hand over sensitive…

July 17, 2026
Hackers Recruit Insiders With Cash and Referrals

Hackers Recruit Insiders With Cash and Referrals

A TrendAI (Trend Micro) report describes a structured underground market where criminals recruit employees to provide access, approve transactions, and bypass controls, often via Telegram and hacking forums. The article gives concrete examples (e.g., paying a FedEx employee $1,000/day to update…

August 7, 2026
Deepfake OnlyFans Catfish Scam Hits Fans

Deepfake OnlyFans Catfish Scam Hits Fans

Scammers are using AI deepfakes to impersonate real OnlyFans creators on social media and trick fans into paying for “live chats” or exclusive interactions. Victims are funneled from TikTok to private messages (e.g., Snapchat) and then pressured to send money via Cash App, after which the scam…

August 7, 2026
TikTok Resin Art “DM to Order” Scam

TikTok Resin Art “DM to Order” Scam

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct messages (and sometimes off-platform), they request deposits or full payment and then disappear, or they try to extract personal/banking…

July 24, 2026
Fake “FBI Agents” Target Scam Victims in DMs

Fake “FBI Agents” Target Scam Victims in DMs

The FBI’s IC3 warns that scammers are impersonating FBI/IC3 staff on social media and messaging apps, especially targeting people who have already been scammed. The criminals use convincing branding (logos, fake reviews) and may even use AI-generated deepfake videos to pressure victims into…

July 21, 2026
Fake Céline Dion Tickets Trap Fans on Facebook

Fake Céline Dion Tickets Trap Fans on Facebook

Scammers are approaching Céline Dion fans on Facebook and steering them into paying for “tickets” outside official resale channels. Victims may even receive a real-looking Ticketmaster transfer link, but scammers send the same ticket to multiple buyers so only the first person scanned at the venue…

July 15, 2026