Docusign - Tool

Threat entity extracted from intelligence sources

Frequency
31
occurrences
First Seen
November 10, 2025
Last Seen
July 4, 2026

Docusign is a tool tracked across 22 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity July 4, 2026.

Overview

DocuSign is a widely used legitimate e-signature platform that is frequently abused in phishing campaigns. Adversaries impersonate DocuSign notifications or e-signing requests to trick recipients into clicking malicious links or divulging credentials, leveraging the platform's trusted status in business workflows.

Related Threat Clusters

Recent Intelligence Reports

  • Sekoia's EvilTokens research — www.sekoia.com · July 4, 2026
  • Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns — Cybersecuritynews · June 16, 2026
  • UAE's most dangerous cyber threat: Why credential phishing is getting harder to detect — Gulfnews · June 16, 2026
  • UAE's most dangerous cyber threat: Why credential phishing is getting harder to detect — Gulfnews · June 16, 2026
  • FBI warns Kali365 phishing kit is stealing Microsoft OAuth tokens at scale — Theregister · May 22, 2026
  • ocean.security — www.globenewswire.com · May 19, 2026
  • Amazon SES increasingly abused in phishing to evade detection — Bleepingcomputer · May 4, 2026
  • Most phishing now uses AI, says KnowBe4 — Theregister · April 30, 2026

CVSS v3.1 Breakdown