source: https://gdpr.eu/gdpr-consent-requirements/ on other legal bases for processing: Processing is necessary to satisfy a contract to which the data subject is a party.
The legitimate interest one is pretty fuzzy, what would the legitimate interest be here? "I want their data" isn't enough, I'm pretty sure.
A contract could transfer users, assuming regulations are followed and users were acquired legitimately (both of which are debatable here). However a contract that requires to transfer users without notice nor consent is defacto null because it is not lawful.
These are extremely serious considerations for the case at hands. Companies knew what they were doing, the acquisition and PII transfer is not merely accidental, that should be covered in the contract. Depending on the wording and the intent of the companies (and any public backslash that might ensue and bring things to light), either side might lawyer up and reconsider the contract, or a third party like a regulator might jump in (could fine the parties or void the acquisition).
With GDPR that can be a maximum 4% of global turnover, so "massive" is a bit of an understatement.
$272m isn't small change for each infringement, and there's millions of them here
[0] https://www.businessofapps.com/data/linkedin-statistics/