Word to the wise: Beware of fake Docusign emails
ID: cdeef132-d871-539d-b177-0adf001c52fa
STIX ID: report--cdeef132-d871-539d-b177-0adf001c52fa
Feed Name: WeLiveSecurity (ESET Research)
The article warns about DocuSign-branded phishing and social engineering, explaining common lures (spoofed envelopes, QR-code attachments, fake Microsoft logins, and abuse of legitimate DocuSign accounts/APIs), the risks of credential theft and subsequent network access, and red flags users should check (destination URLs, presence of security codes, lack of attachments, language errors, sender mismatches). It recommends mitigations including user awareness training, MFA, strong unique passwords with a manager, layered email/web security, stricter funds-transfer verification, policy updates, and reporting to [email protected], and outlines incident response steps such as password resets, malware scans, device isolation, monitoring for data leakage and unusual activity, and performing forensics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
