€10M Deal Hid a Power of Attorney Trap

Hacker Noon Cybersecurity · Medium sophistication
Last updated August 5, 2026

A foreign investor signed transaction documents for a €10M land purchase after being told one document would “protect the company.” The document instead granted broad power of attorney and sale-like authority, and the investor discovered the issue only 18 months later when the local lawyer stopped responding. The case highlights how over-reliance on a single adviser and lack of independent review can quietly transfer control.

Key findings

  • A document presented as protective actually “functioned as a power of attorney combined with a sale authorization,” granting broader authority than the investor understood.
  • The investment’s governance depended on “almost entirely on one professional relationship,” with no independent legal review and no secondary adviser receiving executed copies.
  • The problem went undetected for “eighteen months,” until the investor reviewed the investment and the lawyer “stopped responding.”
  • Once broad authority was delegated, “recovering control became considerably more difficult than acquiring the asset.”

Who’s being targeted

  • Commonly targeted roles: Executives, Business owners/founders, Finance teams, Legal/Compliance, Investment/Corporate development.
  • Affected industries: Investment management / asset management, Cross-border real estate investment, Professional services (legal, fiduciary).
  • Attack channels: physical.
  • Impersonated: Local counsel / trusted fiduciary (as the investor’s adviser).

Awareness takeaways

  • Never sign authority-granting documents (power of attorney, sale authorization, signing authority) without independent review focused only on your interests.
  • Avoid single points of failure: ensure executed documents and key reporting go to more than one trusted party.
  • Treat delegated authority as something to monitor over time, not a one-time closing task.
  • Assume relationships can change and design governance so control cannot be quietly concentrated elsewhere.

Red flags to watch for

  • A document described as protective but it “granted far broader authority than he understood”
  • No independent review before signing and no second adviser receives executed copies
  • Single adviser controls preparation, explanation, custody of signed documents, and ongoing local communications
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine a €10 million deal… and one extra document you’re told will “protect the company.” In this real case, that “protective” paper actually functioned as a power of attorney plus sale authorization, giving someone else legal power to act, even sell, on the investor’s behalf. Here’s the scary part: the entire €10M investment relied almost entirely on one local adviser. No independent legal review, no second adviser copied on the signed set, and for eighteen months, no one noticed how much control had been handed away. Your move: if any document grants power of attorney, signing authority, or sale authorization, pause and send it for truly independent review, someone whose only job is to protect your side.

MITRE ATT&CK techniques

Similar attacks

AI Vishing Works Because Scripts Persuade

AI Vishing Works Because Scripts Persuade

Researchers tested AI and human voice scam calls and found people comply mainly because the caller’s script is persuasive, not because the voice sounds perfectly human. Even when listeners correctly suspect the voice is synthetic, many still continue the conversation and may hand over sensitive…

July 17, 2026
Fraudsters Can Remotely “Brick” Phones for $3

Fraudsters Can Remotely “Brick” Phones for $3

Researchers showed that attackers can abuse mobile carriers’ “lost/stolen phone” reporting process to get devices blocked from the cellular network, even when the devices were never lost. With only a prepaid account and a target device’s IMEI number, blocking can cost just a few dollars and take…

September 11, 2026
Deepfake ‘Kidnapping’ Calls and the Safe Word Fix

Deepfake ‘Kidnapping’ Calls and the Safe Word Fix

The article describes how scammers use AI voice cloning to impersonate a loved one during a phone call and pressure relatives into paying money (often framed as a kidnapping emergency). It recommends a practical defense: a pre-agreed family “safe word” and a simple verification process (hang up and…

September 10, 2026
DPRK Fake Hires Spread to Healthcare & Sales

DPRK Fake Hires Spread to Healthcare & Sales

Investigations found suspected North Korean operatives getting hired into real companies by impersonating other people, including roles outside IT such as healthcare and sales/marketing. The workflow relies on fake or stolen identity documents, remote-access tooling, and deception during interviews…

August 31, 2026
Call-Blocker Seller Fined for Cold-Calling Elderly

Call-Blocker Seller Fined for Cold-Calling Elderly

UK regulator ICO fined Elderly Aids Ltd £190,000 for making over 758,000 unsolicited marketing calls to people who had registered to avoid such calls. Complainants said the callers used aggressive, misleading tactics and sometimes failed to identify themselves, pressuring elderly targets into paid…

August 27, 2026
Phone Scammers Used Fear to Sell €4,000 of Fake Filters

Phone Scammers Used Fear to Sell €4,000 of Fake Filters

A real phone scam convinced an elderly woman that her drinking water was unsafe and pressured her into buying four overpriced “water filters,” costing about €4,000. The article also describes common Portugal-targeted scams, including “Hi Mum/Hi Dad, I lost my phone” money-transfer fraud and SMS…

August 14, 2026