Back Eset Docusign phishing emails: How to spot and stop attacks before it's too late
In the online world, trust is a currency that cybercriminals love getting their hands on. It’s why the likes of Microsoft, Google, and Apple regularly top the list of most-impersonated brands. It’s also why a growing number of malicious actors are looking to abuse the trust that users have in Docusign.
With over a billion users worldwide, the now ubiquitous document-signing service has exactly the kind of reach that makes phishing campaigns effective. And increasingly, the tech vendor’s own infrastructure is being hijacked to bypass traditional security filters. If your business relies on sender trust alone to tackle incoming threats, it may already be exposed.
Read on to learn how Docusign email scams work today, how to verify messages safely, and how you can stop attacks before they take a financial toll on your company.
Docusign email scams can vary in quality and sophistication. But they have a limited set of goals. It’s usually one of the following:
The most basic variant of these threats is a legitimate-looking Docusign email featuring a malicious link in the body of the message, which you are urged to follow in order to sign or view business documents. You will then be taken to a phishing page designed to harvest your details or install malware on your device/PC.
However, there are more sophisticated versions, including:
OAuth consent phishing: Here, instead of a phishing page, the link takes you to a legitimate Microsoft or Google sign-in page asking you to grant permissions to a third-party app (often called something like "DocuSign Secure Integration" or "DocuSign Signature Service"). Accepting will enable the threat actor to retrieve an OAuth Token, meaning they can log into that service as you without requiring your password or MFA code.
QR code phishing (quishing): A Docusign-branded phishing email contains an attachment (typically a PDF) featuring a QR code which you are urged to scan. Doing so with your phone may mean transferring to a less-secure interface where the end goal may be credential harvesting or malware installation.
Abuse of legitimate Docusign infrastructure: Attackers typically compromise legitimate Docusign user accounts and use the Docusign Envelopes API to send malicious documents containing malware, phishing links, or fraudulent invoices. Because the email has been sent via Docusign’s servers, it will bypass your DMARC, SPF, and DKIM email authentication checks.
If you’re unsure whether a Docusign email is legitimate or not, do not click on anything in the message. Instead:
If the document loads, the email is legitimate. If no document is found, it is fraudulent. No redirects. No guesswork. No risk.
A Docusign email is almost certainly malicious if any of the following are true:
Threat actors could use Docusign phishing techniques (e.g. credential harvesting, OAuth consent) to access your email account. This access can then be used to monitor your inbox for invoices and payment approvals.
They could then send a convincing invoice request impersonating a legitimate supplier. Or use your email account to launch phishing/BEC attacks on your colleagues or business partners. Remember: Docusign is not a payment processor. Any request for payment or banking changes must be verified through known vendor portals or out-of-band confirmation.
Today’s phishing actors use a range of sophisticated techniques to hide from security tools and make their campaigns more effective. These include:
In the event of a worst-case scenario, speed matters. Act fast to minimize risk.
To effectively mitigate Docusign threats, you’ll need more than sender filtering. Consider enforcing your security posture with:
Protect what matters - your business and your
Phishing scams and online threats don’t stop at the office. While ESET Small Business Security keeps your business safe, ESET Security Ultimate protects your family and personal life.
“DocuSign, even more than other well-known business software solutions, is an obvious target for cybercriminals because of the data it handles — contracts, business agreements, and other highly sensitive documents. By mimicking a brand trusted by millions of companies, and most Fortune 500 companies, attackers try to gain victims' trust and increase their success rate. According to ESET telemetry, the end of 2025 saw a sharp uptick in HTML/Phishing.DocuSign detections – a 250% increase compared with the first half of the year. Zooming out further, the quality of fraudulent messages masked as DocuSign has also improved over the last few years, with many polished enough that even careful users may struggle to distinguish them from legitimate ones. This makes multi-layered email security measures – including perimeter, server, network-wide, and endpoint solutions, as well as user awareness trainings – crucial for effective defense.”
- Ondrej Kubovič, Security Awareness Specialist
Docusign has become the de facto standard for document signing. But ubiquity makes it a popular target for scammers. They’re using increasingly sophisticated techniques to trick you into handing over credentials, providing MFA-resistant access, paying fraudulent invoices, and installing malware. Some even use legitimate Docusign accounts to do their dirty work.
That’s why individuals and businesses need a more sophisticated response. User awareness is important. But so are updated policies, tighter DMARC controls, improved monitoring, and click-time analysis.
If you rely on sender trust alone to mitigate Docusign risks, you may already be compromised.
These scams typically aim to steal your credentials for services like Microsoft 365 or Google Workspace, trick you into installing malware, or deceive finance teams into paying fraudulent invoices.
With over a billion users, it is a globally trusted brand. Attackers capitalize on this familiarity and trust.
No. While companies can customize certain parts of the email, legitimate Docusign notifications always originate from the @docusign.com or @docusign.net domains. Any email from a generic address like Gmail or an unfamiliar domain is a scam.
Never for the purpose of signing. Real Docusign emails use an embedded "Review Document" button that links directly to its secure site.
Manually go to in your browser. Click "Access Documents" at the top of the page. Paste the 32-character security code from the email. If the document doesn't load there, the email is fraudulent.
Not necessarily. Cybercriminals often compromise real Docusign accounts to send phishing emails which can bypass your security checks.
Act immediately to change your email and Docusign passwords, enable MFA, and run a full malware scan on your computer. You may also need to run more detailed forensics to hunt for signs of wider infection.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
