Skip to content
Saturday 29 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,824.26
+0.29%
DAX
26,569.99
+0.77%
CAC 40
8,401.18
+0.98%
STOXX 50
6,485.67
+0.95%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
Thursday 12 May 2016 11:02 pm

Why M&A activity leaves companies vulnerable to cyber criminals

By: William Turvill

Add as a preferred source on Google

Global merger and acquisitions (M&A) activity reached record-breaking deal values in 2015 at over $5 trillion. Whilst these vast sums excite shareholders, they also attract cyber criminals who sense an opportunity via inherent weaknesses in the M&A process.

In much the same way that insider trading can (if undetected) yield huge returns for the perpetrator, cyber criminals can similarly capitalise by gaining access to sensitive market information.

And firms going through M&A are arguably at their weakest from a security perspective with disruption to their ‘business as usual’ processes.

Read more: UK execs are worried about the economy – but want to do lots of M&A deals

Cyber criminals thrive on this disruption and there are anecdotal cases where the M&A process is thought to have been targeted.

In December 2015, the FBI warned that a criminal group ‘FIN4’ was seeking to facilitate securities fraud. A few months before that FIN4 was implicated in the attempted infiltration of 100 publicly traded companies or advisory firms that provide M&A services such as investor relations, legal counsel and investment banking.

Also in 2015, the Marriott Corporation announced on that it was to acquire the Starwood Hotels Group. Just four days later, Starwood released a statement that it had been the victim of malware breach. Third-party assessment of this acquisition questioned whether the Marriott Corporation had sufficiently probed the M&A process as a potential threat risk.

Read more: Why Brexit vote should not be used as scapegoat for falling M&A activity

Why are firms at particular risk during the M&A process?

Put simply, the M&A process is a perfect storm of high potential reward for criminals combined with more opportunities for them to exploit it.

Both the potential buyer and the seller are potential targets – in effect doubling the potential weak links in the chain.

Companies that (rightly) normally keep their most confidential information to a handful of trusted confidents suddenly find it needs to be shared with a host of lawyers, consultants and other third parties as part of due diligence – increasing the risk of it ending up in the wrong hands.

The insider risk is heightened too with employees that could be subject to undesirable change potentially liable to become disenfranchised and open to criminal overtures.

Read more: TalkTalk profits show fallout from last year's cyber attack

So what can firms do about this?

It’s critical that the parties involved look at themselves through the eyes of an attacker and seek to understand the threats that tend to occur at the various stages of the M&A process.

Security must be a forethought, not an afterthought. Throughout the discussions, and before plugging in the network cable or allowing the two networks to connect, organisations must be sure to understand what’s on the other side, and what risks they could present.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

Related Topics

  • M&A

Trending Articles

  • Pensioners to hand over bank statements in government benefits crackdown

  • Jamie Carragher: HMRC petitions for Sky Sports star to be declared bankrupt

  • Brewdog founder James Watt hits out at ‘total silence’ over new venture

  • Jamie Vardy bags Bundesliga rights as he steps up streaming war with Neville and Lineker

  • Lloyds Bank and Halifax users unable to use app in latest outage

More from Morning Wire

  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • Iranian hackers behind UK energy plant attack

    Energy
    UK industrial electricity prices are the highest in the G7 and 46 per cent above the average of the International Energy Agency.
  • The Simon Levy case proves some criminals can never be rehabilitated

    Opinion
    Simon Levy, a man with dark hair and a beard, looking directly at the camera.
  • Stansted Airport owner hit with cyber attack as millions of customers’ data stolen

    Transport & Infrastructure
    London Stansted Airport is part of the wider Manchester Airports Group (MAG).
  • Banning vape shops won’t fix scuzzy high streets

    Opinion
    High street vape shop Ecigwizard next to Costa Coffee and Subway, with people walking and sitting outside.
  • FTSE 100 Beazley profit plunges as war roils insurance market

    Insurance
    Beazley 2026 business forecast graph with financial data and growth trends displayed for February 24 analysis
  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook