The DocuSign Email That Wasn’t – A Three-Redirect Credential Harvest
ID: dbc3c3a0-d637-5c48-a190-4e9236d2bc7d
STIX ID: report--dbc3c3a0-d637-5c48-a190-4e9236d2bc7d
Feed Name: Security Boulevard
Threat Score
A targeted phishing campaign used a realistic DocuSign "Review & Sign" lure that redirected through Google Maps to an Amazon S3-hosted page mimicking Microsoft 365 to harvest credentials. The redirect chain bypassed URL scanners and standard email authentication checks (SPF/DKIM/DMARC), but IRONSCALES detected a behavioral mismatch between sender infrastructure and claimed brand identity and quarantined the message within 90 seconds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
