The DocuSign That Lived on an S3 Bucket (and Couldn't Decide Who Sent It)
ID: ba746d67-40ae-5369-a877-db6f51a035ec
STIX ID: report--ba746d67-40ae-5369-a877-db6f51a035ec
Feed Name: IRONSCALES
Threat Score
**Executive Summary:** A credential-harvesting phishing campaign impersonated DocuSign using a compromised Georgia K‑12 Google Workspace account that passed SPF/DKIM/DMARC; the malicious "Review Document" CTA pointed to an attacker-controlled AWS S3 bucket hosting a fake signing page, and IRONSCALES' behavioral AI flagged and quarantined the messages — the report includes IoCs, MITRE mappings, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
