This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users were targeted with a “critical security alert” phishing email pushing a malicious app to steal wallet backups.
How the M&A wire fraud scam worked
In this scheme, attackers impersonated a company executive or a supposedly reputable adviser and framed an acquisition as a tightly controlled, confidential transaction involving only a small group of people. Legal and finance staff were pressured to move the conversation off normal company channels and onto WhatsApp or personal email, citing confidentiality. The attackers then pushed for an international wire transfer, supported by forged acquisition documents, while emphasizing that a public announcement was imminent.
Why the pretext succeeded
The scam leaned on urgency, secrecy, and authority at the same time. Framing the deal as confidential discouraged targets from checking with colleagues, while the compressed timeline between the NDA and the supposed announcement reduced the chance that anyone would pause to verify the request through normal channels. Impersonating executives or a trusted adviser added a layer of authority that made the unusual channel switch seem justified rather than suspicious.
The Trezor phishing email
Separately, Trezor users received an email titled Critical Security Alert: STM32 Entropy Vulnerability after Trezor's email provider, Brevo, was breached. The email was not from Trezor and directed recipients to download an app that asked them to enter their wallet backup, effectively asking victims to hand over the seed phrase that protects their cryptocurrency. Trezor explicitly warned customers not to click the link.
DoppelCart and cloned online stores
A large-scale operation known as DoppelCart used more than 119,000 domains to run fake e-commerce shops. Each site copied a real brand's photos and page text, then undercut the brand's prices to attract buyers. Notably, these fake stores republished the real brand's own support contact address, so customers who were charged fraudulently ended up complaining to the legitimate company rather than the scammers.
What to watch for and how to build resistance
- Treat any request to move sensitive business discussions to WhatsApp or personal email as a red flag, especially when framed as confidential.
- Require out-of-band verification and formal approval steps for wire transfers tied to urgent or secretive deals.
- Never enter a wallet backup or seed phrase into an app or website reached through an email link; assume this is theft.
- Before buying from an online store, confirm you are on the brand's official domain, and be skeptical of prices that are unusually low compared to the real site.
- Encourage legal, M&A, finance, and procurement teams to report unusual channel-switching requests and unfamiliar payment demands immediately.
Key findings
- Attackers impersonated executives and used confidentiality pressure to move M&A conversations to WhatsApp and personal email, then attempted to initiate international wire transfers using forged acquisition documents.
- Trezor warned customers about a phishing email with the subject “Critical Security Alert: STM32 Entropy Vulnerability” sent after its email provider Brevo was breached; the lure directed users to download an app and enter their wallet backup.
- A large-scale fake e-commerce network (“DoppelCart”) used over 119,000 domains to clone real brands and steal payment card details, often reusing the real brand’s support contact so complaints go to the legitimate company.
Who’s being targeted
- Commonly targeted roles: Legal, M&A, Finance/AP, Executives, All employees (phishing awareness), Procurement.
- Affected industries: Private equity, Legal services, Financial services, E-commerce/Retail, Cryptocurrency/FinTech, Government services (digital identity).
- Attack channels: email, whatsapp, website.
- Impersonated: Company executive (senior leadership) and/or a “reputable adviser” on the deal, Trezor Security/Support, A cloned version of a legitimate retail brand.
Red flags to watch for
- Pressure to shift work conversations to WhatsApp/personal email
- Unusual secrecy/limited distribution claims (“only a small group involved”)
- Rushed timeline between NDA and “public announcement”
- Security alert email pushing an app download
- Any request to enter a wallet backup/seed phrase
- Unexpected link claiming urgent action is required
- Prices that seem too good to be true (undercutting the real brand)
- Domain/storefront that is not the brand’s official website
- Customer support contact details that don’t match normal brand channels
Frequently asked questions
How does the M&A wire fraud scam work?
Attackers impersonate executives or a trusted adviser, claim a confidential acquisition is underway, and pressure legal and finance staff to move discussions to WhatsApp or personal email before requesting an international wire transfer using forged acquisition documents.
What was the Trezor phishing email about?
Trezor warned that an email titled Critical Security Alert: STM32 Entropy Vulnerability was a phishing attempt sent after its email provider was breached, directing users to download an app and enter their wallet backup.
What is DoppelCart?
DoppelCart is a large-scale fake e-commerce operation using over 119,000 domains to clone real retail brands, undercut their prices, and steal payment card details, while reusing the real brand's support contact so complaints go to the legitimate company.
What should employees do if asked to move a deal conversation to WhatsApp?
Treat the request as a major warning sign, refuse to shift sensitive discussions off approved channels, and verify the request through known internal contacts before taking any action.
Read the video transcript
Imagine this: your GC gets a secret M&A email from the CEO, NDA attached, announcement 'imminent,' and a note to move everything to WhatsApp. That’s the setup: someone masquerading as execs and 'reputable advisers,' pushing legal to WhatsApp and personal email so they can rush forged acquisition docs and an international wire. Same playbook hits Trezor users: email titled 'Critical Security Alert: STM32 Entropy Vulnerability' telling you to click a link, download an app, and type in your wallet backup, your entire crypto, gone. If a deal or a ‘security alert’ email ever pushes you to WhatsApp, personal email, or to enter a wallet backup, stop and verify it yourself using our official internal channels, before you move a cent.