Skip to Content

Got an Unexpected Offer to Buy Your Business? It Might Be a Phishing Scam. +5 Red Flags to Spot it.

Published on April 02, 2025
Last updated on April 2, 2025

I recently received an email with a subject line that caught my eye: someone wanted to acquire Banshee Cybersecurity. Cue the raised eyebrow and a bit of excitement. The message was polite, professional-sounding, and seemingly legit. But something felt... off. Could this be a phishing scam? As a cybersecurity professional, I decided to take a closer look. What I found is something every small business owner should be aware of: not every opportunity is what it seems.

In this post, I break down the anatomy of the email I received, the red flags I spotted, and how you can protect yourself from phishing and social engineering attempts masked as "business opportunities."

The Email That Sparked Concern

The email, from someone claiming to represent a private equity network, was simple and short:

Phishing email message reads, "We have a private equity firm in our network that is highly interested in acquiring Banshee Cybersecurity LLC. Given their mandate, this opportunity is a very strong fit. Can we set up a time to discuss?"

Sounds great, right? But here's the thing:

  • There was no mention of who the firm was.
  • The domain name in the email led to a parked website.
  • There was zero personalization beyond my name and business.

When I first read the email, something didn’t sit right. It reminded me of stories I’ve heard from other founders—a message that seems exciting at first but quickly unfolds into something more concerning. That gut feeling? It wasn’t wrong. It triggered an alert: could this be phishing?

Phishing, after all, isn’t always about fake login pages or bank alerts. Sometimes, it’s dressed up in business suits and acquisition language. At its core, phishing is a scam where attackers pose as trusted figures to trick you into giving up sensitive data—like passwords, financial info, or insights about your business. These messages are crafted to look polished, professional, and trustworthy. But behind the curtain, they’re designed to exploit your trust.

5 Red Flags That Made Me Suspicious

Unsolicited Acquisition Inquiry: I was not actively advertising the sale of my business so this was a caution point for me. Scammers often cast wide nets to lure you in with vague language and lack of details to entice you to reply to learn more. Be aware of these scams whether you are trying to sell your business or not. 

Generic Messaging

The original message had no specifics about my company – again, wide nets. If you receive an email with no mention of your specific services, location, or anything that shows they actually researched your company? It's probably a mass email.

Suspicious Domain & No Online Presence

A legitimate private equity firm would almost certainly have an active site with company information. Reputable firms have real websites with team, portfolios, and a mission.They likely have a presence on social media, business directories, government databases, etc. (e.g. LinkedIn, Crunchbase, Google Business, Corporate Filings). 

I wanted to know more about their company so I searched for it. I did not go to their direct domain. Instead, I looked them up through Google. The search results revealed a company with a very similar name and professional website – leading me to believe this was a poorly executed brand impersonation attempt. Their actual domain led me to a parked domain notice - I didn’t even have to click on the link to see this. Porkbun, the domain registrar, made it clear that this website was a “parked domain”.

Image of the google search for the suspicious parked domain

Still curious, I used Whois and ICANN to dig a bit deeper. ICANN displayed an interesting message indicating it failed to find the site. A normal search result would display the domain name, and registration information. 

ICANN Lookup error

WhoIs revealed very little information about the owner but showed the domain had only been created a few months prior. That sealed the deal – this was likely a scam. 

Who is search showing registration date only a few months prior

Cloud Server Origins

The message came from an AWS EC2 server. These are commonly used in spam and scam campaigns. By default, Amazon has restricted email traffic over port 25 but abuse can still occur. Many spammers also use generic cloud environments to run campaigns anonymously and affordably. You can find this in the original email metadata.  

example of email meta data showing ec2 instance

SPF, DKIM, and ARC Authentication

At first glance, the SPF and DKIM passed the vibe check. But upon closer inspection, the email header didn’t align with the DKIM domain. This misalignment is subtle, but it can indicate domain spoofing or misconfiguration – both of which are red flags. 

example of email meta data showing sPF DKIM and ARC checks

Why These Emails Are Dangerous

These kinds of emails are often the starting point for more serious social engineering attacks. If you respond, they might:

  • Lure you into revealing sensitive business info or financial details. They might say something like, “You’re business seems like the perfect fit, we’ll just need a deposit to perform the valuation.”
  • Send a fake acquisition agreement or contract loaded with malware. It might sound like, “I’m glad we’ve chatted, I’ll just send that contract over to get us started.”
  • Try to move you into a high-pressure situation to "act fast". The scammer urges you by saying, “The market is filling up fast and my client is ready to move. We have to act now. You don’t want to miss this opportunity.”

Even if they don’t have malicious attachments, they're often collecting information to build a more sophisticated attack or resell your data.

What to Do If You Get One & How to Future-Proof Your Biz

If it feels off, trust your gut. This is your company – you’ve built it from the ground up. Here are a few things you should do when you get one of these emails:

  • Don’t respond right away. Take a moment to research. Google their company to determine if they have a web presence.
  • Look up the sender and their domain. You can use open source tools like WhoIs and ICANN to help you investigate. If it’s a parked site or brand-new domain, beware. Does the company resemble or mimic a bigger more well known company? It's likely an impersonation attempt. 
  • Verify through other channels. Contact the supposed company directly using info from a verified source.
  • Report it. Mark as spam or report phishing through your email provider.
  • Train your team – especially executives. These types of scams often target decision-makers. 
  • Limit public exposure. Don’t list personal publicly if you can avoid it.
  • Talk to a cybersecurity pro. It never hurts to have a second set of eyes.

Stay Sharp, Stay Secure

Small business owners are often targeted because they wear many hats and may not have dedicated security teams. But a little skepticism goes a long way.

At Banshee Cybersecurity, we believe in proactive prevention, not fear-based reactions. If something feels off, it probably is. And if you're unsure? We're here to help. Reach out to our team on our contacts page.

© 2026 banSHEE cybersecurity. All rights reserved. Branding and web design by Small Business Cultivator
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram