DocuSign Lure Targets Tech Exec Credentials

Cloud Security Alliance · Medium sophistication
Last updated July 30, 2026

Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and entering login details. The emails use compromised legitimate business mailboxes and realistic context (including copied email threads) to appear trustworthy, then route victims to fake Google Workspace/Gmail-style login pages to steal credentials.

How the Attack Worked

This campaign impersonated DocuSign to target tech executives with document-signing lures. One version used a subject line referencing a document ready for review, prompting recipients to click a Review Document button and later enter a security code on what appeared to be Docusign.com. A second version referenced a specific agreement, such as a share transfer and subscription agreement, and included a pasted-in email thread between multiple companies to appear more legitimate. Both variants ultimately led victims to a fake CAPTCHA and a Gmail or Google Workspace lookalike login page designed to harvest credentials.

Why It Succeeded

The emails were sent from compromised legitimate business email accounts rather than newly registered domains. This helped the messages pass DMARC checks and avoid spam filtering, since the sending infrastructure was technically legitimate even though the content was malicious. The use of a real prior email thread added a layer of social proof, making the request look like a continuation of an existing business conversation rather than a cold, suspicious message. Links were also routed through a legitimate marketing service before reaching the credential-harvesting page, adding another layer of apparent legitimacy to the click path.

What to Watch For

  • Unexpected DocuSign requests urging immediate review or signature
  • Sender addresses tied to third-party organization mailboxes rather than expected DocuSign notification sources
  • Overly long or unusual filenames in subject lines, including multiple file extensions
  • Links that route through marketing or redirect services instead of a clear DocuSign domain
  • Login pages requesting Gmail or Google Workspace credentials after clicking a document link, especially when paired with a CAPTCHA step

Building Resistance

Defenders and executives should verify any unexpected DocuSign request by logging into DocuSign directly and checking Documents or using the Access Code feature, rather than clicking email links or buttons. Sender addresses should be checked directly rather than trusting the display name shown by an email client, particularly when a message includes what looks like an ongoing conversation thread. Organizations should also flag and treat as suspicious any messages that fail SPF, DKIM, or DMARC checks, and encourage users to report unexpected document-signing requests. Because credentials captured through these pages can be reused for follow-on attacks like business email compromise, quick reporting and verification steps are key to limiting downstream impact.

This pattern reflects known techniques such as spearphishing links, impersonation, and credential harvesting through fake web pages, documented under MITRE ATT&CK references including attack.mitre.org/techniques/T1566/002 and attack.mitre.org/techniques/T1656.

Key findings

  • Campaign used DocuSign-branded spearphishing emails targeting tech executives.
  • Emails were sent from compromised legitimate Japanese business email accounts to help pass DMARC checks and avoid spam filtering.
  • Lures claimed a document was ready for review/signature and used a “Review Document Button” or document-themed subject lines.
  • Links routed through a legitimate marketing service (GetResponse) and/or to a malicious site hosting obfuscated JavaScript.
  • Phishing flow presented a fake CAPTCHA and Gmail/Google Workspace lookalike page to capture credentials.
  • Stolen credentials were intended for follow-on attacks such as BEC scams or resale on marketplaces.

Who’s being targeted

  • Commonly targeted roles: Executives, IT, Security Awareness, Finance, Legal, Corporate Development.
  • Affected industries: Technology / Information, Any business using e-signature platforms (cross-industry).
  • Attack channels: email, website.
  • Impersonated: DocuSign.

Red flags to watch for

  • Unexpected DocuSign request urging action to review/sign
  • Sender domain is a third-party organization mailbox rather than an expected DocuSign notification source
  • Link routes through a marketing/redirect service instead of a clear DocuSign URL
  • Overly long/odd filename in the subject (multiple extensions / “Copy.docx_…pdf”)
  • Email contains a pasted thread to create false legitimacy
  • Landing page mimics Gmail/Google Workspace login (credential request unrelated to DocuSign)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the DocuSign phishing emails avoid spam filters?

The campaign was sent from compromised legitimate business email accounts, which helped the messages pass DMARC checks and avoid being flagged as spam.

What happens after clicking the Review Document link?

Victims are routed through a marketing redirect service or a malicious site hosting obfuscated JavaScript, eventually landing on a fake CAPTCHA and a Gmail or Google Workspace lookalike page that captures their credentials.

Why did the emails include an existing email thread?

Attackers pasted in a legitimate-looking thread between multiple companies to make the phishing email appear more credible and trustworthy.

What should stolen DocuSign credentials be used for by attackers?

According to the findings, stolen credentials were intended for follow-on attacks such as business email compromise scams or resale on marketplaces.

Read the video transcript

You get an email: “BIYH-QPVSW-3617 is ready for your review” with a big blue “Review Document” button. Looks like DocuSign, right? In a real campaign, this came from a compromised Japanese business account, not DocuSign. The link ran through a GetResponse tracking URL, then dropped victims on a fake CAPTCHA and a Gmail-style login page to steal their Google Workspace credentials. Another version says, “Please Docusign this document: Share transfer & Subscription Agreement_062024.docx Copy.docx_PM5235627.pdf” and pastes a whole prior thread. The giveaway? That weird multi-extension filename and a DocuSign email that suddenly wants your Gmail password. Here’s the move: if a DocuSign email is unexpected, don’t touch the button. Open DocuSign in your browser yourself and check for the document there.

Similar attacks

Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026