Just in:

DocuSign reveals ‘non-core’ system breach powered phishing expedition

locksecurity

DocuSign has revealed a data breach that has allowed malicious actors to conduct a wide-ranging phishing campaign.

In a notice on its website, DocuSign said it found the breach when investigating the cause of an increase in DocuSign-impersonating phishing emails.

ADVERTISEMENT

“A malicious third party had gained temporary access to a separate, non-core system that allows us to communicate service-related announcements to users via email,” the company said.

“A complete forensic analysis has confirmed that only email addresses were accessed; no names, physical addresses, passwords, social security numbers, credit card data, or other information was accessed.

“No content or any customer documents sent through DocuSign’s eSignature system was accessed; and DocuSign’s core eSignature service, envelopes and customer documents and data remain secure.”

According to DocuSign, the phishing emails have the subject lines: “Completed: [domain name] – Wire transfer for recipient-name Document Ready for Signature” and “Completed [domain name/email address] – Accounting Invoice [Number] Document Ready for Signature”.

It recommends forwarding the malicious emails to [email protected] and deleting them.

A full copy of the email template can be found on TechHelpList.com, which said the messages contain a .doc file that downloads password and bank-credential stealing malware.

Recently appointed DocuSign CEO Daniel Springer said in January that the company was IPO ready.

“It could go public in any market,” Springer said. “It’s more just thinking through what’s the right time for this business.”

Former CEO Keith Krach moved onto the board of the San Francisco-based company.

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
UAE Scrutinizes Report on Racial Discrimination Treaty // Andertoons by Mark Anderson for Thu, 25 Apr 2024 // Etihad Airways Announces Paris Service with A380 // ESG Achievement Awards 2023/2024 is Open for Application, Celebrating Innovative Sustainable Practices and Responsible Risk Management // Dubai Gears Up for Second FinTech Summit as Funding Surges // Sharjah Census Gears Up for Final Enumeration Phase // Hong Kong Unveils April 30 Launch for Landmark Crypto ETFs // Cobb’s Game-Changer: Introducing One-Stop Event Transport Management Solution // Telecom Giant Du Eyes Crypto Integration for FinTech Platform // Booming Region Fuels Innovation Surge // Galaxy Macau’s Sakura Cultural Festival Kicked off in Splendor // PolyU forms global partnership with ZEISS Vision Care to expand impact and accelerate market penetration of patented myopia control technology // NetApp’s 2024 Cloud Complexity Report Reveals AI Disrupt or Die Era Unfolding Globally // Lee Chong Wei Shows Up On Chinese Hot cultural Talk Show “SHEDE Wisdom Talents”, Talking About “Crossing The Hill” // Leading with Compliance, ZUHYX Earns the Canadian MSB License // UAE President, Spanish Prime Minister Hold Phone Talks // DIFC Courts Cement Role as Top English Dispute Resolution Choice // New Dynamics in Cryptocurrency Security: ZUHYX Builds the Strongest Fund Protection System // GE Jun, Chairman and CEO of TOJOY, Delivers an Inspiring Speech: “Leaping Ahead Again” // Cairo Recognizes Arab World’s Creative Luminaries at Award Ceremony //