The growing threat of Docusign phishing attacks (2024)

saikatsg 14 points 9 comments July 29, 2026
www.darktrace.com · View on Hacker News

Discussion Highlights (4 comments)

wiml

I sometimes enjoy reading through my spam folder. I get a lot of docusign phishing (despite not being an important executive). I also get a lot of "docusing" phishing, which gives me a chuckle. Is it bardic spam?

thewebguyd

Docusign could put a stop to a good chunk of these but they choose not to. They know attackers are abusing their free trial service to send these out using docusign's own domains. Just gate the trial behind a sign-up/sales call.

effnorwood

Hey Siri, what is DKIM?

paultopia

Honestly I’m shocked this took so long. For years and years this has smelled like a massive vulnerability to me, just because so constantly I find myself getting docusigns from people I have some kind of business with, without any warning in advance that it’s coming. At least a couple times a year I find myself calling some banker/travel organizer/administrator in charge of some speaking fee/etc./etc. and asking “hey, I have some Docusign with a weird name on it in my inbox, is that from you?” (See also, every process within a million miles of the mortgage industry, which seems almost custom-made by fraudsters to help other fraudsters, like the whole practice of mailing out letters saying “Surprise! A servicer change happened, now you need to send a check to this totally other company you’ve never heard of! Trust us, it’s real!”)

Semantic search powered by Rivestack pgvector
15,380 stories · 143,452 chunks indexed