logo

The DocuSign Email That Wasn’t – A Three-Redirect Credential Harvest

ID: dbc3c3a0-d637-5c48-a190-4e9236d2bc7d

STIX ID: report--dbc3c3a0-d637-5c48-a190-4e9236d2bc7d

Feed Name: Security Boulevard

Threat Score
65/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Themis

...
...

A targeted phishing campaign used a realistic DocuSign "Review & Sign" lure that redirected through Google Maps to an Amazon S3-hosted page mimicking Microsoft 365 to harvest credentials. The redirect chain bypassed URL scanners and standard email authentication checks (SPF/DKIM/DMARC), but IRONSCALES detected a behavioral mismatch between sender infrastructure and claimed brand identity and quarantined the message within 90 seconds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.