logo

The DocuSign That Lived on an S3 Bucket (and Couldn't Decide Who Sent It)

ID: ba746d67-40ae-5369-a877-db6f51a035ec

STIX ID: report--ba746d67-40ae-5369-a877-db6f51a035ec

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-16

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

**Executive Summary:** A credential-harvesting phishing campaign impersonated DocuSign using a compromised Georgia K‑12 Google Workspace account that passed SPF/DKIM/DMARC; the malicious "Review Document" CTA pointed to an attacker-controlled AWS S3 bucket hosting a fake signing page, and IRONSCALES' behavioral AI flagged and quarantined the messages — the report includes IoCs, MITRE mappings, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.