Skip to content
Saturday 15 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,750.11
-0.21%
DAX
26,440.31
+0.53%
CAC 40
8,636.80
-0.16%
STOXX 50
6,539.59
-0.09%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Thursday 12 May 2016 11:02 pm

Why M&A activity leaves companies vulnerable to cyber criminals

By: William Turvill

Add as a preferred source on Google

Global merger and acquisitions (M&A) activity reached record-breaking deal values in 2015 at over $5 trillion. Whilst these vast sums excite shareholders, they also attract cyber criminals who sense an opportunity via inherent weaknesses in the M&A process.

In much the same way that insider trading can (if undetected) yield huge returns for the perpetrator, cyber criminals can similarly capitalise by gaining access to sensitive market information.

And firms going through M&A are arguably at their weakest from a security perspective with disruption to their ‘business as usual’ processes.

Read more: UK execs are worried about the economy – but want to do lots of M&A deals

Cyber criminals thrive on this disruption and there are anecdotal cases where the M&A process is thought to have been targeted.

In December 2015, the FBI warned that a criminal group ‘FIN4’ was seeking to facilitate securities fraud. A few months before that FIN4 was implicated in the attempted infiltration of 100 publicly traded companies or advisory firms that provide M&A services such as investor relations, legal counsel and investment banking.

Also in 2015, the Marriott Corporation announced on that it was to acquire the Starwood Hotels Group. Just four days later, Starwood released a statement that it had been the victim of malware breach. Third-party assessment of this acquisition questioned whether the Marriott Corporation had sufficiently probed the M&A process as a potential threat risk.

Read more: Why Brexit vote should not be used as scapegoat for falling M&A activity

Why are firms at particular risk during the M&A process?

Put simply, the M&A process is a perfect storm of high potential reward for criminals combined with more opportunities for them to exploit it.

Both the potential buyer and the seller are potential targets – in effect doubling the potential weak links in the chain.

Companies that (rightly) normally keep their most confidential information to a handful of trusted confidents suddenly find it needs to be shared with a host of lawyers, consultants and other third parties as part of due diligence – increasing the risk of it ending up in the wrong hands.

The insider risk is heightened too with employees that could be subject to undesirable change potentially liable to become disenfranchised and open to criminal overtures.

Read more: TalkTalk profits show fallout from last year's cyber attack

So what can firms do about this?

It’s critical that the parties involved look at themselves through the eyes of an attacker and seek to understand the threats that tend to occur at the various stages of the M&A process.

Security must be a forethought, not an afterthought. Throughout the discussions, and before plugging in the network cable or allowing the two networks to connect, organisations must be sure to understand what’s on the other side, and what risks they could present.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

Related Topics

  • M&A

Trending Articles

  • Revolut takes flight with launch of new airport lounges

  • Grandparents fund university degrees to avoid inheritance tax net

  • Revolut chatbot goes rogue by charging users to cancel subscription

  • Brompton Bicycle sues former adviser for ‘professional negligence’

  • As It Happened: Stocks dip as oil’s ‘slowing demand’ in focus; Iran threatens to extend war

More from Morning Wire

  • AI gold rush leaves accountancy firms exposed to costly cyberattacks

    AI
    Two tablets displaying code and a cyber warning symbol, with blurry blue and pink background numbers
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • M&S chair: Tax and employment costs holding back Britain

    Retail
    Archie Norman, business leader, speaking at a corporate event wearing a suit and tie, engaging with the audience.
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • The Simon Levy case proves some criminals can never be rehabilitated

    Opinion
    Simon Levy, a man with dark hair and a beard, looking directly at the camera.
  • Accertify and Liminal Release First Empirical Study Proving Fraud-Cyber Convergence Works – and Defining How to Do It Right

    Business Wire
  • Banning vape shops won’t fix scuzzy high streets

    Opinion
    High street vape shop Ecigwizard next to Costa Coffee and Subway, with people walking and sitting outside.
  • As it happened: FTSE 100 rises to defy tech gloom; oil creeps up on fresh Iran tensions

    Markets
    Donald Trump with hand on chin, appearing contemplative during a public event, wearing a suit and red tie.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook