logo

Hackers Create Fake DocuSign Login Page to Steal User Credentials

ID: cce610ac-951d-5911-95ff-6d3aabed971e

STIX ID: report--cce610ac-951d-5911-95ff-6d3aabed971e

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers observed an ongoing DocuSign impersonation phishing campaign that leverages the LogoKit phishing framework and legitimate hosting (IPFS gateways, AWS S3) to dynamically assemble convincing fake login portals that harvest credentials; indicators include SPF failures, mismatched Reply-To headers, and URLs passing recipient emails as parameters, and defenders are advised to enforce SPF/DKIM/DMARC, deploy advanced email protections, and train users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.