Cybercriminals Exploit DocuSign API to Send Convincing Phishing Invoices at Scale
ID: 5826efea-d10a-540a-8dfa-7fc3d417148b
STIX ID: report--5826efea-d10a-540a-8dfa-7fc3d417148b
Feed Name: securityonline.info
Wallarm researchers warn of a rising phishing campaign where attackers register paid DocuSign accounts and use the Envelopes API and manipulated templates to send realistic fraudulent invoices (e.g., Norton-branded) that bypass typical email filters and ask victims to authorize payments; the report details the technique, observed increases in community reports, and recommends multi-layered defenses including sender verification, internal approvals, employee training, anomaly monitoring, and API rate limiting/behavior profiling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
