40000 Phishing Emails Disguised as SharePoint and and e-Signing Services
The hyperconnected world has made it easier than ever for businesses and consumers to exchange documents, approve transactions, and complete critical financial workflows with just a click. Digital file sharing and electronic signature platforms used widely across banking, real estate, insurance, and everyday business operations, have become essential to how modern organizations move at speed. But that same convenience creates an opening for cyber criminals.
Email security researchers at Check Point have recently uncovered a phishing campaign where attackers impersonate file-sharing and e-signature services to deliver finance-themed lures that look like legitimate notifications.
In this incident, attackers sent over 40,000 phishing emails targeting roughly 6,100 customers over the past two weeks. All malicious links were funneled through increasing trust by mimicking familiar redirect flows.
The attackers abused Mimecast’s secure-link rewriting feature , using it as a smokescreen to make their links appear safe and authenticated. Because Mimecast Protect is a trusted domain, this technique helps malicious URLs bypass both automated filters and user suspicion.
To boost credibility, the emails copied official service visuals (Microsoft and Office products logos), used service-style headers, footers, and “review Document” buttons, and spoofed display names such as “ X via SharePoint (Online) ”, “ eSignDoc via Y ”, and “ SharePoint ”, closely matching authentic notification patterns.
Related Variant: DocuSign-Style Phishing Using a Different Redirect Method
Alongside the large SharePoint/e-signing campaign, researchers also identified a smaller but related operation that imitates DocuSign notifications. Like the primary attack, it impersonates a trusted SaaS platform and leverages legitimate redirect infrastructure, but the technique used to mask the malicious destination differs significantly.
In the main campaign, the secondary redirect acts as an open redirect, leaving the final phishing URL visible in the query string despite being wrapped in trusted services. In the DocuSign-themed variant, the link moves through a Bitdefender GravityZone URL and then Intercom’s click-tracking service, with the true landing page fully hidden behind a tokenized redirect. This approach conceals the final URL entirely, making the DocuSign variant even more stealthy and harder to detect.
Image 1: Example of a phishing email we intercepted.
Image 2: Example of a phishing email from the DocuSign-style variant of the campaign.
The campaign primarily targeted organizations across the U.S., Europe, Canada, APAC, and the Middle East, focusing heavily on consulting, technology, and construction/real estate sectors, with additional victims spanning healthcare, finance, manufacturing, media and marketing, transportation and logistics, energy, education, retail, hospitality and travel, and government. These sectors are attractive targets because they routinely exchange contracts, invoices, and other transactional documents, making file-sharing and e-signature impersonation lures highly convincing and more likely to succeed.
Data from Check Point’s Harmony Email telemetry shows that over 40,000 phishing emails targeting roughly 6,100 customers over the past two weeks. The campaign primarily targeted organizations across the U.S., Europe, Canada, APAC, and the Middle East. By region, the breakdown is as follows:
Note: Regional distribution reflects where customer data is hosted within our infrastructure and does not necessarily represent customers’ physical locations.
Now we’ve written similar phishing campaigns in years, but what makes this attack unique is that it shows how easily attackers can imitate trusted file-sharing services to trick users and highlights the need for continued awareness, especially when emails include clickable links, suspicious sender details, or unusual email body content.
Organizations and individuals must also take proactive steps to reduce their risk. A few ways to stay protected include:
Statement from Mimecast:
The attacker campaign described by Check Point exploited legitimate URL redirect services to obfuscate malicious links, not a Mimecast vulnerability. Attackers abused trusted infrastructure – including Mimecast’s URL rewriting service – to mask the true destination of phishing URLs. This is a common tactic where criminals leverage any recognized domain to evade detection.
Mimecast customers are not susceptible to this type of attack. Mimecast’s detection engines identify and block these attacks. Our URL scanning capabilities automatically detect and block malicious URLs before delivery. After delivery, our URL rewriting service inspects links on click, providing an additional layer that catches threats even when they’re hidden behind legitimate redirect chains.
We continue to enhance our protections against evolving phishing techniques. Customers can review our analysis from 2024 of similar campaigns here:
We appreciate Check Point sharing their findings through responsible disclosure.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
