The Fake NDA Attack: What Business Leaders Need to Know
Fake NDA Threat: What Is It?
A Fake NDA attack is a targeted phishing tactic designed to steal login credentials.
The attacker sends what appears to be a legitimate nondisclosure agreement from a:
- Prospect
- Customer or business partner
- Investor
- Vendor or supplier
The target is often an executive, salesperson or business development professional — someone accustomed to receiving NDAs as part of everyday business.
Why does it work? NDAs are associated with opportunity. A new deal, partnership or customer may be on the other side. That creates a natural incentive to respond quickly rather than stop and verify.
What Does It Look Like?
The email may look completely routine:
“Please review and sign the attached NDA.”
Instead of a traditional attachment, you’re directed to a familiar-looking link or document-sharing platform.
Clicking the link takes you to a fake login page designed to resemble Microsoft, Google, DocuSign or another trusted file-sharing service.
You’re asked to log in to view or sign the document.
That’s the trap.
The moment you enter your username and password, the attacker may have your credentials.
The Threat Actor Gained Access. Now What?
Stolen credentials can give an attacker a foothold inside your organization.
From there, they may be able to:
- Access or monitor email
- Impersonate executives or employees
- Target customers, vendors or coworkers
- Attempt fraudulent payments
- Steal sensitive business information
- Use the compromised account to move deeper into the organization
One fake NDA can quickly become a much larger business problem.
Tips to Prevent This Attack
- Be cautious with unexpected NDAs. Even when the sender or opportunity appears legitimate.
- Don’t enter credentials from an email link. Especially if you’re unexpectedly asked to log in again.
- Verify the sender separately. Call, text or start a new email using contact information you already trust.
- Use trusted platforms. Access documents by navigating directly to the service rather than following an unexpected link.
- Report suspicious requests immediately. Early reporting can help your organization investigate before others are targeted.
- Share this threat with your team. Sales, executives and anyone who regularly handles NDAs should know what to watch for.

The SensCy Solution
We provide an affordable, easy-to-understand, sensible solution specifically tailored to each client. Our clients tell us that they are thrilled with the value that they derive for the price they pay. Schedule a consultation with one of our experts.

Your SensCy Score® is a good indication of your organization’s cyber hygiene and how prepared your organization is against cyber threats. We can generate your score in less than 30 minutes—at no cost to you!
Recent Posts
