ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    DocuSign Phishing Attacks

    IT Discussion
    7
    10
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NerdyDadN
      NerdyDad
      last edited by

      This is to say the least. I've gotten a number of these emails last week.

      http://newsletter.knowbe4.com/a/1022/preview/323/171782/e95164e747c36173e00b01800cc0298761d59e80?message_id=ImI4MzY4ZjkwLTIxMjQtMDEzNS0yMGY5LTBjZGNkNGI2MzRjNEBrbm93YmU0LmNvbSI=
      0_1495461991669_docusign.PNG

      bogdan.moldovanB 1 Reply Last reply Reply Quote 1
      • Deleted74295D
        Deleted74295 Banned
        last edited by

        We ditched DocuSign because their API was limited to Enterprise only plans at a crazy amount of money.

        For a company that is selling trust in the form of digital signatures, a breach like this is pathetically embarrassing.

        JaredBuschJ 1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @Deleted74295
          last edited by

          @Breffni-Potter said in DocuSign Phishing Attacks:

          We ditched DocuSign because their API was limited to Enterprise only plans at a crazy amount of money.

          For a company that is selling trust in the form of digital signatures, a breach like this is pathetically embarrassing.

          WTF are you talking about?

          FFS, this is just a basic phishing email and has nothing to do with DocuSign getting breached.

          Deleted74295D DashrenderD 2 Replies Last reply Reply Quote 2
          • NashBrydgesN
            NashBrydges
            last edited by

            C'mon, it's only a Russian domain. What harm could there be in clicking the link 😉

            1 Reply Last reply Reply Quote 1
            • Deleted74295D
              Deleted74295 Banned @JaredBusch
              last edited by Deleted74295

              @JaredBusch said in DocuSign Phishing Attacks:

              @Breffni-Potter said in DocuSign Phishing Attacks:

              We ditched DocuSign because their API was limited to Enterprise only plans at a crazy amount of money.

              For a company that is selling trust in the form of digital signatures, a breach like this is pathetically embarrassing.

              WTF are you talking about?

              FFS, this is just a basic phishing email and has nothing to do with DocuSign getting breached.

              http://newsletter.knowbe4.com/a/1022/preview/323/171782/e95164e747c36173e00b01800cc0298761d59e80?message_id=ImI4MzY4ZjkwLTIxMjQtMDEzNS0yMGY5LTBjZGNkNGI2MzRjNEBrbm93YmU0LmNvbSI=

              The phishing was based on three breaches.

              1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller
                last edited by

                We've been getting these emails too.

                1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @JaredBusch
                  last edited by

                  @JaredBusch said in DocuSign Phishing Attacks:

                  @Breffni-Potter said in DocuSign Phishing Attacks:

                  We ditched DocuSign because their API was limited to Enterprise only plans at a crazy amount of money.

                  For a company that is selling trust in the form of digital signatures, a breach like this is pathetically embarrassing.

                  WTF are you talking about?

                  FFS, this is just a basic phishing email and has nothing to do with DocuSign getting breached.

                  But they were breached - you know that right? And many of their customers have reported getting phished since the breach happened.

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Dashrender
                    last edited by

                    @Dashrender said in DocuSign Phishing Attacks:

                    @JaredBusch said in DocuSign Phishing Attacks:

                    @Breffni-Potter said in DocuSign Phishing Attacks:

                    We ditched DocuSign because their API was limited to Enterprise only plans at a crazy amount of money.

                    For a company that is selling trust in the form of digital signatures, a breach like this is pathetically embarrassing.

                    WTF are you talking about?

                    FFS, this is just a basic phishing email and has nothing to do with DocuSign getting breached.

                    But they were breached - you know that right? And many of their customers have reported getting phished since the breach happened.

                    Might be unrelated. We aren't a customer.

                    JaredBuschJ 1 Reply Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @scottalanmiller
                      last edited by

                      @scottalanmiller said in DocuSign Phishing Attacks:

                      @Dashrender said in DocuSign Phishing Attacks:

                      @JaredBusch said in DocuSign Phishing Attacks:

                      @Breffni-Potter said in DocuSign Phishing Attacks:

                      We ditched DocuSign because their API was limited to Enterprise only plans at a crazy amount of money.

                      For a company that is selling trust in the form of digital signatures, a breach like this is pathetically embarrassing.

                      WTF are you talking about?

                      FFS, this is just a basic phishing email and has nothing to do with DocuSign getting breached.

                      But they were breached - you know that right? And many of their customers have reported getting phished since the breach happened.

                      Might be unrelated. We aren't a customer.

                      Correct. This is a phishing email. While data involved from their breach may well have been used to seed some emails for better luck in getting responses, the email itself is simply a phishing email.

                      I have them in multiple client admin accounts and I know that there are no Docusign users at these clients.

                      1 Reply Last reply Reply Quote 0
                      • bogdan.moldovanB
                        bogdan.moldovan @NerdyDad
                        last edited by

                        As everybody noticed, the delivery vector for these phishings is email. So an email filtering engine that is capable of detecting phishing attacks, either by recurrent pattern detection (like Cyren), or via URL extraction and checks (like Kaspersky or BitDefender), when in place, will keep your users safe. These phishing emails are also caught by open source engines like the veteran SpamAssassin or the new kid on the block OrangeAssassin (from SpamExperts).

                        1 Reply Last reply Reply Quote 2
                        • 1 / 1
                        • First post
                          Last post