Fake M&A Wire Fraud and Trezor Phishing Alert

The Hacker News · Medium sophistication
Last updated September 11, 2026

This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users were targeted with a “critical security alert” phishing email pushing a malicious app to steal wallet backups.

How the M&A wire fraud scam worked

In this scheme, attackers impersonated a company executive or a supposedly reputable adviser and framed an acquisition as a tightly controlled, confidential transaction involving only a small group of people. Legal and finance staff were pressured to move the conversation off normal company channels and onto WhatsApp or personal email, citing confidentiality. The attackers then pushed for an international wire transfer, supported by forged acquisition documents, while emphasizing that a public announcement was imminent.

Why the pretext succeeded

The scam leaned on urgency, secrecy, and authority at the same time. Framing the deal as confidential discouraged targets from checking with colleagues, while the compressed timeline between the NDA and the supposed announcement reduced the chance that anyone would pause to verify the request through normal channels. Impersonating executives or a trusted adviser added a layer of authority that made the unusual channel switch seem justified rather than suspicious.

The Trezor phishing email

Separately, Trezor users received an email titled Critical Security Alert: STM32 Entropy Vulnerability after Trezor's email provider, Brevo, was breached. The email was not from Trezor and directed recipients to download an app that asked them to enter their wallet backup, effectively asking victims to hand over the seed phrase that protects their cryptocurrency. Trezor explicitly warned customers not to click the link.

DoppelCart and cloned online stores

A large-scale operation known as DoppelCart used more than 119,000 domains to run fake e-commerce shops. Each site copied a real brand's photos and page text, then undercut the brand's prices to attract buyers. Notably, these fake stores republished the real brand's own support contact address, so customers who were charged fraudulently ended up complaining to the legitimate company rather than the scammers.

What to watch for and how to build resistance

  • Treat any request to move sensitive business discussions to WhatsApp or personal email as a red flag, especially when framed as confidential.
  • Require out-of-band verification and formal approval steps for wire transfers tied to urgent or secretive deals.
  • Never enter a wallet backup or seed phrase into an app or website reached through an email link; assume this is theft.
  • Before buying from an online store, confirm you are on the brand's official domain, and be skeptical of prices that are unusually low compared to the real site.
  • Encourage legal, M&A, finance, and procurement teams to report unusual channel-switching requests and unfamiliar payment demands immediately.

Key findings

  • Attackers impersonated executives and used confidentiality pressure to move M&A conversations to WhatsApp and personal email, then attempted to initiate international wire transfers using forged acquisition documents.
  • Trezor warned customers about a phishing email with the subject “Critical Security Alert: STM32 Entropy Vulnerability” sent after its email provider Brevo was breached; the lure directed users to download an app and enter their wallet backup.
  • A large-scale fake e-commerce network (“DoppelCart”) used over 119,000 domains to clone real brands and steal payment card details, often reusing the real brand’s support contact so complaints go to the legitimate company.

Who’s being targeted

  • Commonly targeted roles: Legal, M&A, Finance/AP, Executives, All employees (phishing awareness), Procurement.
  • Affected industries: Private equity, Legal services, Financial services, E-commerce/Retail, Cryptocurrency/FinTech, Government services (digital identity).
  • Attack channels: email, whatsapp, website.
  • Impersonated: Company executive (senior leadership) and/or a “reputable adviser” on the deal, Trezor Security/Support, A cloned version of a legitimate retail brand.

Red flags to watch for

  • Pressure to shift work conversations to WhatsApp/personal email
  • Unusual secrecy/limited distribution claims (“only a small group involved”)
  • Rushed timeline between NDA and “public announcement”
  • Security alert email pushing an app download
  • Any request to enter a wallet backup/seed phrase
  • Unexpected link claiming urgent action is required
  • Prices that seem too good to be true (undercutting the real brand)
  • Domain/storefront that is not the brand’s official website
  • Customer support contact details that don’t match normal brand channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the M&A wire fraud scam work?

Attackers impersonate executives or a trusted adviser, claim a confidential acquisition is underway, and pressure legal and finance staff to move discussions to WhatsApp or personal email before requesting an international wire transfer using forged acquisition documents.

What was the Trezor phishing email about?

Trezor warned that an email titled Critical Security Alert: STM32 Entropy Vulnerability was a phishing attempt sent after its email provider was breached, directing users to download an app and enter their wallet backup.

What is DoppelCart?

DoppelCart is a large-scale fake e-commerce operation using over 119,000 domains to clone real retail brands, undercut their prices, and steal payment card details, while reusing the real brand's support contact so complaints go to the legitimate company.

What should employees do if asked to move a deal conversation to WhatsApp?

Treat the request as a major warning sign, refuse to shift sensitive discussions off approved channels, and verify the request through known internal contacts before taking any action.

Read the video transcript

Imagine this: your GC gets a secret M&A email from the CEO, NDA attached, announcement 'imminent,' and a note to move everything to WhatsApp. That’s the setup: someone masquerading as execs and 'reputable advisers,' pushing legal to WhatsApp and personal email so they can rush forged acquisition docs and an international wire. Same playbook hits Trezor users: email titled 'Critical Security Alert: STM32 Entropy Vulnerability' telling you to click a link, download an app, and type in your wallet backup, your entire crypto, gone. If a deal or a ‘security alert’ email ever pushes you to WhatsApp, personal email, or to enter a wallet backup, stop and verify it yourself using our official internal channels, before you move a cent.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Crypto Newsletter Breach Triggers Fake Security Emails

Crypto Newsletter Breach Triggers Fake Security Emails

Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking,…

September 10, 2026