Phishing Attack Leverages DocuSign to Steal Outlook Logins
Researchers have identified cybercriminals leveraging DocuSign to conduct phishing attacks to steal Microsoft Outlook login credentials. Around 550 members of a "major, publicly traded integrated payments solution company located in North Americaā€¯ received phishing emails containing a fake DocuSign link asking for Outlook login credentials. Once the credentials were entered, they went directly to the hackers.
While this specific attack is targeting company personnel, BlackCloak advises all DocuSign users to be on the lookout for any emails coming from unknown domains. In this case, the phony emails belong to a domain called "TermBrokersInsurance." If you have any questions about suspicious communications, contact the BlackCloak Concierge Assistance team and we will help determine the legitimacy of the message.