Merger, Acquisition, Forgotten Domain: How M&A Activity Quietly Expands Your Attack Surface

AUGUST 11, 2026

Every merger and acquisition closes with a handover document. Asset lists, systems inventories, license agreements, infrastructure diagrams. These documents are the output of weeks or months of due diligence: financial, legal, operational, and increasingly, technical. But there is a category of asset that almost never appears in a handover document, because the organization being acquired did not know it existed, and neither did the acquirer until an attacker found it first.

Forgotten domains. Abandoned subdomains. Cloud accounts that were provisioned for a campaign that ended two years ago and were never decommissioned. Legacy application environments still receiving traffic from old DNS records pointing to infrastructure that has not been patched since the previous administration. These are the assets that survive a transaction invisibly, carrying with them the security debt of the organization that created them, now inherited by an acquirer whose security team does not know to look for them.

The moment an acquisition is announced, threat actors begin mapping the target’s external surface. They are not waiting for the handover document. They are scanning certificate transparency logs, passive DNS databases, and historical WHOIS records to find every domain, subdomain, and IP range that has ever been associated with the target entity. The acquiring organization inherits those exposures whether or not they appear in any internal inventory. The attackers already know the full picture. The security team does not.

62% of executives say acquiring new companies introduces significant cybersecurity risks (Forescout)52% of organizations discover major security risks only after deal close, in integration (Infosys)30% more externally exposed assets than security teams realize in the average enterprise (IBM)73% of dealmakers say an undisclosed breach is an immediate deal-breaker (Infosys)

What Gets Inherited That Nobody Inventoried

The scope of the inherited attack surface in a typical acquisition is substantially larger than the acquiring organization expects. Research published in 2025 found that the average enterprise has 30% more externally exposed assets than its security team is aware of. In the context of an acquisition, where the acquirer starts from zero visibility into the target’s external footprint, the gap is routinely much larger. Organizations that have run EASM assessments immediately post-close consistently report finding assets that represent years of unmanaged infrastructure accumulated by the acquired company.

These assets fall into predictable categories that repeat across every acquisition, regardless of sector or company size.

Forgotten Domains and Lapsed Registrations

Every organization accumulates domain registrations over time: product launch domains, regional variations of the main brand, marketing campaign microsites, domains registered for acquisitions that never closed, or names purchased defensively to prevent brand squatting. Over years of operation, many of these domains become disconnected from any active service but remain registered, sometimes pointing at infrastructure that still responds, sometimes simply accumulating in a registrar account that nobody checks.

When a company is acquired, these domains transfer with the legal entity. The acquiring organization’s IT team inherits a collection of domain registrations it has never seen and has no process for. Some will lapse in the months following the acquisition when auto-renewal fails on a credit card that no longer exists. When a corporate domain lapses, it can be registered by anyone, including threat actors who exploit the residual trust that the domain carries with browsers, email systems, and existing business relationships.

Abandoned Subdomains and Dangling DNS

Subdomains accumulate faster than domains. Every product feature, every regional deployment, every third-party integration, every development environment gets a subdomain. Organizations routinely create subdomains for projects that end, services that get decommissioned, or integrations that get replaced. When the underlying service is removed, the DNS record often remains. This is called a dangling CNAME: a subdomain that points at a cloud service, a CDN, or a SaaS platform that the organization no longer has an account with.

The risk of a dangling CNAME is direct: any attacker who registers the abandoned account on the target platform can claim the subdomain. At that point, they control a subdomain that carries the acquired company’s brand, is trusted by browsers because it resolves correctly, and can serve content, capture credentials, or host phishing pages under a domain that passes basic visual inspection. In 2025, researchers re-registered approximately 150 abandoned cloud storage accounts that had formerly belonged to governments, Fortune 500 companies, and security vendors, demonstrating that this class of exposure is neither theoretical nor rare.

Unpatched Legacy Infrastructure

The assets that carry the highest immediate exploitation risk are internet-facing systems that have not received security updates, whether because the team responsible for them did not know they were still running, because they were deprioritized in favor of active production systems, or because patching them would require downtime that the previous administration could never schedule.

In the manufacturing sector, 42% of M&A deals have faced cybersecurity incidents tied to legacy infrastructure. These systems are often the first targets in post-acquisition campaigns because they represent the path of least resistance: the new security team has not yet mapped them, the old team no longer exists, and the systems themselves have accumulated months or years of unaddressed vulnerabilities.

Cloud Accounts Without Owners

Cloud infrastructure created by the acquired company does not transfer automatically into the acquirer’s cloud governance framework. Developer accounts, departmental cloud subscriptions, staging environments, data pipelines, and object storage buckets provisioned for specific projects may continue running in their original accounts, outside the acquirer’s monitoring tools and access control policies. Credentials for these accounts may exist only in the memories or personal password managers of employees who did not survive the acquisition process.

These accounts represent unmonitored compute and storage infrastructure that may contain sensitive data from the acquired company’s customer base, carry open security group rules that allow inbound traffic from anywhere, and have no process for receiving security patches or configuration audits. They are, in the most direct sense, attack surface that the security team does not know it owns.

What Attackers Do the Moment an Acquisition Is Announced

Dark web forum analysis consistently shows that M&A announcements trigger targeted reconnaissance. Threat actors post about acquisition targets on criminal forums, share infrastructure enumeration results, and discuss the security weaknesses of transition periods, during which IT teams are focused on integration logistics rather than security monitoring. The acquisition announcement is the starting gun. From that moment, the target’s external attack surface, including every forgotten domain and abandoned subdomain, is being actively mapped by actors who want to exploit the window between announcement and full security integration. That window, in most organizations, lasts months.

image 3 - Merger, Acquisition, Forgotten Domain: How M&A Activity Quietly Expands Your Attack Surface

Why Standard Due Diligence Does Not Catch This

Cybersecurity has become a standard component of M&A due diligence. Legal teams request security questionnaires. Technical teams review incident history and compliance certifications. IT teams may audit the target company’s active infrastructure and review network diagrams. Eighty percent of global dealmakers report finding cybersecurity issues in at least one quarter of their acquisition targets in the course of due diligence.

But the standard due diligence process has a structural limitation that makes the forgotten asset problem almost invisible. Due diligence assesses what the target company knows it has. It reviews the systems the target company’s IT team is responsible for, the domains the target company’s web team actively manages, and the cloud infrastructure the target company’s operations team monitors. It does not systematically discover what the target company’s teams have forgotten or never knew about.

The Self-Reported Inventory Problem

Most cybersecurity due diligence begins with a request for the target company to complete an asset inventory: domains, IP ranges, cloud accounts, internet-facing systems. This inventory is necessarily self-reported. It reflects what the target company’s current IT team knows about. It does not reflect the subdomain a departing developer set up three years ago and never documented. It does not reflect the cloud account provisioned by a marketing contractor for a campaign that was cancelled. It does not reflect the legacy application environment that IT decided to leave running because migrating it was too complex.

The assets that create the highest post-acquisition risk are precisely the ones that do not appear in a self-reported inventory. They are the unknown unknowns, and no questionnaire process can surface them, because the organization being questioned does not know the answers.

The Timeline Problem

Even where cybersecurity due diligence is conducted rigorously, the timeline of an M&A transaction creates a window during which the inherited attack surface is unmonitored. Due diligence typically concludes before deal close. The integration process begins after deal close. Between those two points, the inherited infrastructure exists under a legal ownership transition, with uncertain responsibility for monitoring and response. This transition window is exactly the period that threat actors target.

Research indicates that in many cases a threat actor is already present in the target company’s environment before the acquisition closes, having exploited one of the very forgotten assets that due diligence did not surface. The acquirer’s first indication of this presence is often an incident that occurs during integration, when the target’s infrastructure is being connected to the acquirer’s network, creating a lateral movement path that did not previously exist.

The Verizon-Yahoo Precedent

The Verizon acquisition of Yahoo is the defining case study in M&A cybersecurity failure. Two undisclosed data breaches affecting more than three billion accounts were discovered after the acquisition had been announced. The disclosure reduced the acquisition price by 350 million dollars. The final settlement included ongoing obligations for Yahoo’s successor entity and established that an undisclosed breach discovered during or after an M&A transaction creates direct financial liability for the acquired company, the acquiring company, and potentially the executives who signed the deal documents. 73% of dealmakers say an undisclosed breach is an immediate deal-breaker. The Yahoo case is the reason that number is so high. It established that what a company does not know about its own infrastructure is a financial and legal liability, not merely a technical inconvenience

How Inherited Assets Become Active Threats: The Post-Close Timeline

The inherited attack surface does not become dangerous after the acquisition. It becomes visible as a risk after the acquisition, because the acquiring organization’s security team begins discovering it. The actual risk often predates the deal. Understanding the post-close timeline is essential for designing an integration program that addresses the inherited attack surface before it is exploited.

PhaseTimelineInherited Asset Risk ProfileTypical Security Team Focus
AnnouncementDay 0Attacker reconnaissance begins immediately. Target’s full external surface is mapped by threat actors within days of announcement.Deal logistics, PR management. Security not yet engaged on inherited assets.
Pre-close due diligenceWeeks 1-8Self-reported inventory is collected. Unknown assets remain undiscovered. Legacy infrastructure continues running unmonitored.Review of known systems, compliance certifications, incident history. Unknown assets outside scope.
CloseDay NLegal transfer of all infrastructure, including unknown assets, to acquirer. Responsibility without visibility.Integration planning begins. Unknown assets still not mapped.
Early integrationMonths 1-3Highest risk window. Inherited infrastructure being connected to acquirer’s network. Threat actors who established presence pre-close begin lateral movement.Network integration, identity consolidation. Discovery of forgotten assets often begins here, reactively.
Integration stabilizationMonths 3-12Inherited assets that were not found in early integration continue running unmonitored. Some forgotten domains begin lapsing.Active systems integrated. Forgotten assets remain off-radar.
Post-integrationYear 1+Forgotten assets remain as persistent unmonitored exposure. Domain lapse risk increases. Legacy systems accumulate vulnerabilities.Attention shifts to new projects. Inherited unknown assets rarely revisited.

Why EASM Is a Non-Negotiable Step in M&A Due Diligence

External attack surface management addresses the structural limitation of self-reported inventory by discovering assets from the outside in, using the same reconnaissance techniques that attackers use, without requiring the target company’s cooperation or prior knowledge. An EASM assessment of an acquisition target surfaces what the target knows about and what it does not, in the same process, in hours rather than weeks.

This capability makes EASM uniquely suited to the M&A due diligence context. It does not depend on the accuracy of the target’s self-reported inventory. It does not require access to the target’s internal systems. It does not need the target’s IT team to be available or cooperative. It discovers the complete external footprint from publicly available information, exactly as an attacker would, and returns a picture of inherited risk that includes the unknown assets that questionnaire-based due diligence cannot find.

What EASM Provides at Each Stage of the M&A Process

M&A StageWhat EASM ProvidesBusiness Value
Pre-announcementBaseline external footprint of the target before any information sharing; identification of known breaches, exposed credentials, and active threat actor interest in the target’s infrastructureInforms go/no-go decision with visibility into inherited risk that affects deal valuation
Due diligenceComplete external asset inventory independent of target’s self-reported data; discovery of forgotten domains, abandoned subdomains, unpatched legacy systems, and cloud assets outside IT inventorySurfaces the unknown unknowns that traditional due diligence misses; enables accurate risk-adjusted pricing
Pre-closeContinuous monitoring of inherited attack surface for new exposures and active threat actor activity targeting the transactionEarly detection of pre-close compromise attempts; identifies assets requiring immediate remediation post-close
Day-one integrationImmediate visibility into full inherited attack surface for the security team; prioritized remediation list based on exploitability and business impactEliminates the discovery gap between deal close and security team awareness; reduces lateral movement risk from inherited infrastructure
Post-integration monitoringOngoing discovery of new assets created by the acquired entity; alerts on inherited domain lapses and certificate expirations; detection of credential exposure in dark web marketsPrevents the persistent long-tail risk of forgotten assets that were not addressed in the initial integration window

The Seed Set Problem: Why EASM Must Start from Entity, Not Domain

An EASM program that starts from a list of known domains will find everything connected to those domains. It will not find the domains that are not on the list. In a standard deployment, the security team provides the EASM tool with a seed set of domains and IP ranges, and the tool discovers everything reachable from there.

In an M&A context, this approach fails for exactly the reason that the problem exists in the first place: the unknown assets are unknown because they are not connected to the known seed set. A forgotten domain registered under a subsidiary entity name, a cloud account provisioned with a personal email address by a former employee, a subdomain pointing to infrastructure in a cloud region the acquiring company does not know the acquired company used: none of these appear in a seed-set-based scan.

Effective M&A attack surface assessment requires starting from the organizational entity itself, not from a domain list. This means building from legal entity names, historical domain registrations, certificate transparency logs, WHOIS records, and passive DNS data to construct a complete picture of everything the acquired organization has ever operated on the internet, including the things it has stopped operating but not cleaned up. The difference between entity-first and seed-set discovery is the difference between finding the known assets and finding the complete inherited attack surface.

The Integration Checklist Gap

Most M&A integration checklists include IT system migration, identity consolidation, network integration, and application rationalization. Very few include a line item for external attack surface discovery of inherited assets. The gap is not because security teams do not care about it. It is because the tools required to perform entity-first external discovery have historically been specialized and expensive. EASM as a continuous capability changes this. An organization that already runs EASM against its own footprint can extend the same program to cover an acquisition target from announcement, with no special configuration or additional tooling. The acquisition simply becomes an additional entity in the discovery scope, and the unknown assets surface alongside everything else.

What a Security-Integrated M&A Program Looks Like

Closing the inherited attack surface gap in an M&A process requires four changes to the standard integration program.

1. EASM Assessment Before Due Diligence Begins

The external attack surface assessment of an acquisition target should begin before the target’s security team is engaged in the due diligence process. An entity-first EASM scan of the target, conducted from publicly available data alone, provides a baseline picture of inherited risk that can inform due diligence scope, negotiation posture, and risk-adjusted pricing before any information sharing has occurred.

The output of this pre-engagement scan should directly inform the questions asked in formal due diligence: are there legacy infrastructure assets the target is aware of that this scan surfaced? Are there credentials exposed in dark web markets associated with the target’s domains? Are there subdomains pointing at cloud infrastructure that has been abandoned?

2. Continuous Monitoring From Announcement Through Integration

The period between announcement and full integration is the highest-risk window in the acquisition lifecycle. An EASM program that monitors the inherited attack surface continuously during this period provides early warning of threat actor reconnaissance, pre-close compromise attempts, and the emergence of new exposures in infrastructure that is no longer actively managed by either organization’s security team.

Continuous monitoring during this window is distinct from a one-time due diligence scan. The attack surface changes during the transition period: domains lapse, certificates expire, cloud accounts lose their owners, and new threat actor interest is generated by the public announcement of the deal. Only continuous monitoring catches these changes as they occur.

3. Day-One Remediation Priority List

The integration security program should have a prioritized list of inherited assets requiring immediate remediation ready on day one of post-close integration. This list should be organized by exploitability and business impact: dangling CNAMEs that can be immediately claimed by an attacker, unpatched internet-facing systems with known exploited vulnerabilities, and legacy domains approaching lapse that carry residual brand trust.

The remediation program for inherited assets requires a distinct ownership model from the standard vulnerability management process. Nobody in the acquiring organization previously owned these assets, so they will not appear in any existing owner mapping. A named owner must be assigned for each category of inherited asset before remediation tickets can be routed.

4. Long-Tail Monitoring Beyond the Integration Window

The most dangerous inherited assets are the ones that are not discovered in the initial integration window and persist as unmonitored exposure for months or years after the formal integration program closes. A continuous EASM program that includes the acquired entity’s historical domain registrations and organizational identifiers in its seed set will surface these assets as they become relevant: when a domain approaches lapse, when a certificate expires on a forgotten subdomain, or when credentials associated with an old account surface in a dark web market.

The integration program ends. The inherited attack surface does not.

How Brandefense Supports M&A Attack Surface Management

CapabilityHow It Addresses M&A Attack Surface Risk
Entity-first external asset discoveryBuilds the full organizational entity map for the acquired company before scanning: historical domains, related entities, certificate history, WHOIS records, and passive DNS data, independent of any self-reported inventory
Continuous external attack surface monitoringMonitors the inherited attack surface from announcement through post-integration, detecting new exposures, domain lapse risk, and certificate expiration as they occur rather than at scheduled assessment intervals
Dark web credential monitoring for inherited identitiesDetects credentials associated with the acquired company’s domains and organizational identifiers appearing in infostealer logs and dark web markets, providing early warning of pre-close compromise that did not surface in formal due diligence
Certificate transparency monitoringTracks new SSL certificate issuance for acquired domains and related organizational identifiers, surfacing new internet-facing assets as they are created and detecting lookalike domains registered against the acquired brand
Subdomain and dangling DNS detectionIdentifies abandoned subdomains and dangling CNAME records in the inherited infrastructure, prioritizing those at immediate risk of takeover by external actors
Threat actor targeting intelligenceMonitors dark web forums and threat actor channels for discussions referencing the acquisition target, the transaction itself, or the acquiring organization, providing early warning of threat actor interest that precedes an active campaign
RELATED READING

The 62% Problem: Why Most Enterprises Only See Two-Thirds of Their Real Attack Surface:  https://brandefense.io/blog/the-62-percent-problem-external-attack-surface/ : the structural visibility gap that M&A compounds by adding an entirely new organizational footprint

Shadow IT: Why the Assets Your IT Team Does Not Know About Are Your Most Dangerous Entry Points:  https://brandefense.io/blog/shadow-it-hidden-attack-surface/ : the shadow IT dynamic that exists within any organization and multiplies during an acquisition

62% of Breaches Now Start With a Vendor:  https://brandefense.io/blog/the-rise-of-supply-chain-cyber-attacks/ : how the third-party risk model applies equally to the inherited vendor relationships of an acquired entity

NIS2 and DORA Compliance for TPRM:  https://brandefense.io/blog/nis2-dora-third-party-risk-management/ : the regulatory asset inventory obligations that now apply to inherited infrastructure as well as directly managed assets
Cybersecurity alert about inherited assets and attack surface expansion.
BrandeDefense highlights risks of inherited assets post-acquisition and M&A activities.

SHARE THIS

Get insight, Analysis &
News Straight to Your
Inbox

By submitting this form, you agree to our Privacy Policy

Latest News