July 29, 2026

Signed, sealed, scam-delivered

The Growing Threat of Docusign Phishing Attacks

Fake Docusign emails are everywhere, and commenters say everyone saw this disaster coming

TLDR: Researchers found a phishing campaign using fake DocuSign emails to trick people into handing over passwords, with tech executives in the crosshairs. Commenters were split between dark humor and anger, with many saying this scam feels obvious because surprise DocuSign requests already look suspiciously normal.

The scary part of this phishing wave isn’t just the fake paperwork — it’s how painfully believable it all looks. Researchers say scammers are sending emails dressed up like DocuSign, often claiming a document is waiting for your signature, then pushing victims toward pages designed to steal passwords. In this campaign, tech executives were the target, with some emails even borrowing real business threads to look extra legit. One attack reportedly dangled a fake code entry, then a fake Google-style login page, because apparently cybercriminals now believe in layered theatrical production.

But in the comments, the real fireworks were about whether this is shocking at all. One camp basically said, of course this happened: DocuSign emails arrive so randomly in normal business life that people are trained to click first and ask questions later. Another group was even harsher, accusing DocuSign of leaving the front door open by letting attackers allegedly abuse trial accounts and trusted-looking email systems. That sparked the big mood of the thread: not just fear, but irritation that this feels preventable.

And because the internet cannot resist a joke during a security crisis, commenters also turned the spam folder into open-mic night. There was laughter over misspelled “docusing” scams, a deadpan “Hey Siri, what is DKIM?” for the email-authentication confusion, and general amazement that modern phishing somehow manages to be both sloppy and weirdly convincing at the same time.

Key Points

  • Cado Security Labs, now part of Darktrace, identified a Docusign-themed spearphishing campaign targeting tech executives.
  • The campaign used compromised legitimate Japanese business email accounts to send phishing emails and improve the chance of passing DMARC checks.
  • One analyzed email used a link on app.getresponse.com, which may have served as a tracking or redirection mechanism.
  • A second email included a seemingly legitimate business email thread and linked to a malicious site hosting an obfuscated JavaScript payload named NdoGg8EElI.
  • The script used base64-encoded logic to present a fake Google Workspace/Gmail-style login page and redirect victims to another phishing site for credential theft.

Hottest takes

"docusing phishing, which gives me a chuckle" — wiml
"Docusign could put a stop to a good chunk of these but they choose not to" — thewebguyd
"Honestly I’m shocked this took so long" — paultopia
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.