Docusign API Abused in Widescale, Novel Invoice Attack
ID: c3e3794e-afbc-50cf-ac87-6eda5a3e32d0
STIX ID: report--c3e3794e-afbc-50cf-ac87-6eda5a3e32d0
Feed Name: Dark Reading
Date Published: 2024-11-05
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Security researchers observed a large-scale phishing campaign abusing DocuSign's API to send authentic-looking invoice requests from legitimate, paid accounts and templates. Because the messages are generated through DocuSign, they often evade spam/phishing filters and contain no malicious links or attachments; if signed or paid, they enable financial fraud. The report highlights mitigation steps for organizations (verify senders, internal purchase controls) and for providers (rate limits, threat modeling) to reduce API abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
