logo

Don't fall for a mail asking for rapid Docusign action – it may be an Azure account hijack phish

ID: f45b0f05-ef0b-578e-9b75-22910d5af852

STIX ID: report--f45b0f05-ef0b-578e-9b75-22910d5af852

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-12-19

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Palo Alto Networks Unit 42 tracked a Europe-focused phishing campaign that sent DocuSign-themed PDFs and HubSpot form redirects to ~20,000 targets across automotive, chemical and industrial manufacturing sectors; the actors harvested Azure credentials via fake Outlook Web Access pages and attempted persistence and tenant access, with researchers collecting IoCs and noting infrastructure (some active) while blocking the attackers before major data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.