Beware of Fake Docusign Emails

 

Let this serve as a friendly reminder to refrain from digitally signing documents that you may unexpectedly receive. Such actions may inadvertently provide your digital signature to threat actors (hackers), which could subsequently be exploited for unauthorized financial transactions in your name.

According to Bleeping Computer:

Threat actors are abusing DocuSign's Envelopes API to create and mass-distribute fake invoices that appear genuine, impersonating well-known brands like Norton and PayPal.  

Using a legitimate service, the attackers bypass email security protections as they come from an actual DocuSign domain, docusign.net.

The goal is to have their targets e-sign the documents, which they can then use to authorize payments independently from the company's billing departments.

The best way to avoid this is to double-check that the digital documents you received in your inbox are real and you expect it. If the message simply appears on your inbox unexpectedly, do not sign it immediately.  Verify its authenticity first before taking action.

Comments

Popular posts from this blog

GCash Security Scare: Rethinking the Safety of Digital Wallets

When Malware is Digitally Signed by an Anti-Malware Company

Tech Party List, A Satirical List