BLOG

Address leak leads to phishing

A number of people in the industry are reporting getting phishing emails to addresses they used at DocuSign.

There were initial reports of a DocuSign data breach back in December. Now it appears DocuSign is being used as a phishing target.

At 8:40AM PST this morning, 1/24/2013, DocuSign became aware of new malware spam emails that are being sent as if it was coming from the DocuSign service. An example follows immediately below. These emails are not coming from DocuSign and you should not click on any links or attachments therein. They are coming from an unrelated, malicious third party attempting to copy DocuSign’s email branding in the hopes of fooling recipients into opening the email and clicking on links and/or attachments.

This seems to be a widespread phishing attack. Watch your links.

1 comment

  1. steve says

    I’ve been seeing phishing/malware mails claiming to be from docusign since early December, all to an address that I think was taken from SolarWinds/Eloqua. I’ve also seen “Scanned Image”, “Paychex”, “eFax corporate” and “Wire transfer”.

    No obvious connection to any DocuSign breach, just generic malware mail by the look of it. Without looking closely, I’d guess one of the botnets.

Comment:

Your email address will not be published. Required fields are marked *

  • Ongoing Yahoo delays

    I've been hearing from folks over the last few days that they're seeing an uptick in deferrals from Yahoo! The deferrals are not uniform. ESPs report they're seeing some, but not all, customers affected. Other ESPs aren't seeing any changes. It's not just you. But it would be very worthwhile to dig into engagement and other stats. It's possible this is a new normal at Yahoo! and they're tightening filters to catch mail that doesn't fit their standards but was previously difficult to filter.No Comments


  • AOL starts using Sender Score Certification

    Good news for Sender Score Certified IPs. Return Path recently announced that AOL has joined the list of ISPs offering preferential treatment to certified IPs.  1 Comment


  • iCloud Service Disruption

    40% of iCloud users were affected this morning during a service disruption between 2:15AM and 9:30AM. Apple System StatusNo Comments


Archives