logo

Cybercriminals Exploit DocuSign API to Send Convincing Phishing Invoices at Scale

ID: 5826efea-d10a-540a-8dfa-7fc3d417148b

STIX ID: report--5826efea-d10a-540a-8dfa-7fc3d417148b

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2024-11-07

Date Updated: 2026-04-22

Author: do son

...
...

Wallarm researchers warn of a rising phishing campaign where attackers register paid DocuSign accounts and use the Envelopes API and manipulated templates to send realistic fraudulent invoices (e.g., Norton-branded) that bypass typical email filters and ask victims to authorize payments; the report details the technique, observed increases in community reports, and recommends multi-layered defenses including sender verification, internal approvals, employee training, anomaly monitoring, and API rate limiting/behavior profiling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.