logo

DocuSign's Envelopes API abused to send realistic fake invoices

ID: acde53d3-056f-547c-8bfb-2100b59d1a30

STIX ID: report--acde53d3-056f-547c-8bfb-2100b59d1a30

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-11-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors are abusing DocuSign's Envelopes API to create and mass-distribute authentic-looking fake invoices that impersonate well-known brands (e.g., Norton, PayPal). By using legitimate paid DocuSign accounts and the Envelopes:create endpoint, attackers bypass email security (emails originate from docusign.net), automate high-volume delivery, and seek e-signatures that can be used to authorize fraudulent payments; Wallarm documented the activity and reported it to DocuSign, which says it monitors and takes action against misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.