TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Mergers & Acquisitions
№ 341 Case Study — Mergers & Acquisitions

The Merger That Closed Anyway, Two Days Late and Missing Something

Ngoc and Linh had four business days before their merger deadline expired when a routine document review turned up a vendor email neither of them had ever seen before.

Mergers & Acquisitions8 min readEtobicoke, OntarioCybersecurity diligence
All Mergers & Acquisitions case studies
ClientNgoc, founder of an Etobicoke technology-enabled services company merging with a longtime competitor led by Linh, against a closing deadline that fell over a holiday week
The issueA prior data breach the other side had never disclosed surfaced in vendor correspondence four business days before the closing deadline expired
ServiceAssessed the breach exposure under real time pressure and negotiated protection into the agreement without the closing date moving
ResolutionThe merger closed on schedule with the breach risk allocated to the party that caused it, though the surprise itself could not be undone

The situation

Four business days. That was what stood between Ngoc and Linh and a financing commitment that would expire if the merger did not close on time, and it was the number both of them kept repeating on the call where they first told us what a junior associate had just found buried in a folder of vendor correspondence nobody had prioritized reviewing until closing week was already underway.

Ngoc and Linh ran two competing businesses in Etobicoke, each providing similar technology-enabled services to a mid-market commercial client base. Linh had spent a decade as a construction project manager before founding her company, and still ran it with the same instinct for sequencing and dependencies that the trade had taught her. The two founders had spent the better part of a year negotiating a merger of near-equals rather than a straightforward acquisition of one by the other. The deal sat in the thirty-to-fifty-million-dollar range, structured so that both founders would hold significant ongoing stakes in the combined company, which meant diligence had been more collaborative and less adversarial than a typical arm's-length sale. Vendor contracts, IT infrastructure, and data handling practices were all reviewed, but the review had been split across two smaller teams working independently, on the assumption that a merger of equals did not need the scrutiny of a hostile acquisition.

That assumption turned out to be the gap. The email chain the associate found was between Vartan — the counterparty's head of technology, and a former chiropractor who had left his practice for IT years earlier — and an external security vendor, dated roughly fourteen months earlier, discussing containment of a breach that had exposed a portion of client contact and billing data. It had never appeared in the data room, and it had never come up in any of the dozens of calls between the two sides over the preceding year. Whether it was withheld deliberately or simply fell through the cracks during a chaotic period was not yet clear, and with four business days left, there was not much time to find out before decisions had to be made regardless.

The holiday timing made everything harder. Half the people who might have answered questions quickly were unreachable for at least part of the window, and the financing lender's own team was operating on a skeleton schedule that made even a short extension request slower to process than it would have been on an ordinary week. Ngoc and Linh had spent the past year building what both of them described as a genuine partnership, not just a transaction, and the discovery landed differently because of that. This was not two strangers finding a problem in diligence. It was two people who thought they already trusted each other completely, forced to ask, four days from closing, whether that trust had been misplaced.

What made this urgent

The financing commitment backing the merger was not flexible. It had been negotiated on a fixed timeline months earlier, and the lender's terms included a hard expiry date rather than an automatic extension option, a detail that had seemed like a minor administrative point when the financing was arranged and became the single most important fact in the room once the breach surfaced. If the deadline passed without closing, the entire financing package would need to be renegotiated from scratch, at whatever terms the lender chose to offer a second time, months later, in a different market.

Compounding the timing problem was the holiday week itself. Two of the people whose input mattered most, including someone who had lived through the breach itself, were away and only partially reachable. Getting a straight answer to a basic question, what data was exposed and to how many people, took nearly two full days of the four available, simply because the people who knew were hard to reach.

There was also a harder question sitting underneath the scheduling pressure. A breach that happened fourteen months earlier and was never disclosed during a year of diligence is not just a technical gap, it raises a real question about what else might not have been disclosed, and whether the trust the two founders had built over a year of collaborative negotiation could survive finding out that at least one significant fact had been kept from the process. Ngoc, in particular, was less angry about the breach itself than about learning it existed from a vendor email rather than from Linh or Vartan directly.

Every option in front of Ngoc and Linh by the third day carried a real cost. Walking away from the deal preserved nothing, since both companies had already spent a year and significant money getting to this point, and Ngoc's business had its own financing and staffing decisions already made in reliance on the merger closing. Closing without addressing the breach at all left an unquantified risk sitting inside the combined company indefinitely, one that could resurface as a client notification obligation or a regulatory inquiry at any point after the two companies were legally one entity. Closing with the breach addressed, but imperfectly, in the time available was the only realistic option, and it meant accepting that some questions would not get fully answered before the closing date arrived regardless of how much everyone involved might have preferred otherwise.

What we did

  1. Triaged what could realistically be confirmed in four days versus what could not. With the deadline fixed, we immediately separated the questions that had answers available quickly, like what data category was exposed, from questions that would require a fuller forensic review, like the total number of affected individuals, so the team's limited time went toward what was actually decidable before closing.
  2. Reached the vendor directly rather than waiting on the counterparty's unavailable staff. Because key people on Vartan's side were away for the holiday, we contacted the external security vendor named in the email chain directly, with the counterparty's consent, and obtained their incident summary report within a day, which gave us a factual baseline that did not depend on anyone's memory of events fourteen months old and could not be reconstructed after the fact.
  3. Quantified the realistic exposure rather than treating it as unlimited. The vendor's report showed the breach had affected a defined, bounded set of contact and billing records, not the full client database as the worst initial fear suggested, which meant the negotiation could proceed around an actual, if imperfectly precise, figure rather than an open-ended unknown that neither side could reasonably price into the deal.
  4. Negotiated a specific indemnity carve-out tied to the breach rather than relying on general representations. Rather than trying to unwind or renegotiate the whole agreement in the time available, we added a targeted indemnity provision making Vartan's side responsible, without the general liability caps that applied elsewhere in the agreement, for any loss connected to the undisclosed breach specifically, so the risk sat with the party that created it.
  5. Required notification protocols to be updated as a closing condition. Because the breach had gone unreported even internally for over a year, we required, as a condition to closing, that the combined company's incident response and notification procedures be reviewed and updated within a defined period after closing, so the same kind of gap could not recur inside the newly merged entity going forward.
  6. Pushed the financing lender for a short, narrow extension rather than accepting the original deadline as immovable. With two days left, we approached the lender directly, laid out exactly what remained outstanding and why, and requested a brief extension limited specifically to finalizing the indemnity language. Framing the request narrowly, rather than as an open-ended delay, gave the lender an easy basis to say yes, which they did, buying two additional days without triggering the broader renegotiation both sides had feared.
  7. Documented what remained unknown rather than papering over it. The final agreement included a clear acknowledgment that a full forensic review had not been completed before closing, with a defined process and timeline for completing one afterward. Writing the gap into the document itself, instead of glossing over it, meant neither side was pretending to more certainty than actually existed at the time the final documents were signed.
  8. Set up a joint communication protocol between Ngoc and Linh for the review period ahead. Recognizing that the trust gap mattered as much as the legal exposure, we recommended, and both founders agreed to, a structured weekly check-in through the forensic review process so that findings reached both of them directly and simultaneously, rather than through intermediaries who might unintentionally soften or delay bad news.

The outcome

The merger closed two days after the original deadline, using the short extension the lender granted once the specific reason for it was explained. The financing terms did not change, which was the outcome Ngoc and Linh needed most given how much both businesses had already committed to the deal proceeding, and given how little room either founder had left to absorb a further delay without real cost to their own operations.

This was not a clean win, and describing it as one would misrepresent what actually happened. The breach itself could not be undone, and the fact that it went undisclosed for a year of otherwise collaborative negotiation left a mark on the relationship between the two founders that the indemnity clause could not repair. Ngoc said plainly, weeks after closing, that she trusted Linh and the rest of the leadership team less than she had before the breach surfaced, even though she believed, by that point, that the non-disclosure had been an oversight during a chaotic period rather than a deliberate choice made against her.

The financial exposure was contained. The indemnity carve-out meant that when the completed forensic review, finished about ten weeks after closing, confirmed the breach had affected a limited group of records rather than the full client base, the associated notification and remediation costs were covered under the targeted provision rather than becoming a shared cost of the merged company that both founders would otherwise have absorbed equally. That was a real, meaningful protection, and it kept a bad surprise from becoming a shared financial burden.

It did not, and could not, restore the year of due diligence the two sides thought they had already completed together, or the assumption of full disclosure the merger had originally been built on. The weekly check-ins continued well past the forensic review's completion, less because the legal work required it by that point and more because both founders had decided, on their own, that rebuilding what the closing week had cost them was worth the ongoing effort.

What you can learn from this

  • A merger of equals, structured collaboratively rather than adversarially, can create real gaps in diligence rigour precisely because both sides assume the other is being forthcoming. Some level of independent verification is worth keeping even when the relationship feels trustworthy.
  • A financing commitment with a hard expiry date and no automatic extension option is a risk worth flagging early, well before closing week, since the moment you actually need flexibility is usually the worst possible moment to discover you do not have it.
  • When a serious issue surfaces close to closing, triage what can realistically be confirmed in the time available from what requires a longer investigation, and build the agreement around that honest split rather than pretending a rushed answer is a complete one.
  • A targeted indemnity carved out from general liability caps can allocate a specific, known risk fairly without requiring the whole agreement to be renegotiated under time pressure, which matters most in the exact moment a deadline genuinely cannot move for either side.
  • Contained financial exposure and a repaired relationship are not the same outcome. A well-drafted clause can protect the numbers while the trust between the people involved still takes real time, separate from the legal work, to rebuild or does not fully return at all.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a mergers & acquisitions problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →