logo

Criminals open DocuSign's Envelope API to make BEC special delivery

ID: 21ca5905-3787-503c-a4b6-1dd63e2e21e2

STIX ID: report--21ca5905-3787-503c-a4b6-1dd63e2e21e2

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-11-05

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Wallarm researchers warn that BEC scammers are abusing DocuSign's Envelope:create API by creating paid accounts and crafted templates to send authentic-looking invoices that bypass spam and phishing filters; once signed these invoices can be mass-forwarded to funnel payments to attackers, and the issue has been observed to be growing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.