Menu
Browse

Cyber Incident Victim: DocuSign

Date:

May 2017

Location:

United States of America

Summary

A breach at an electronic signature provider compromised customer email addresses from a non-core system used for service announcements, enabling attackers to launch targeted phishing campaigns impersonating legitimate communications. Malicious emails contained links to malware-infected Word documents disguised as wire transfer instructions, leveraging stolen contact lists to exploit user trust in expected correspondence. The company confirmed no access to core eSignature systems, documents, or sensitive data like passwords or financial information, maintaining that only email addresses were exfiltrated. This incident amplified existing phishing risks for users by providing attackers with validated targets, though legitimate communications could still be verified via direct platform access using unique security codes.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On May 9, 2017, DocuSign disclosed it was tracking a malicious email campaign impersonating its services, with subject lines referencing wire transfer instructions and documents ready for signature. These emails contained links to malware-laden Microsoft Word documents. Initially, DocuSign stated the messages originated from a malicious third party misusing its branding but were unrelated to its systems. Subsequent investigation revealed the campaign stemmed from a breach where attackers gained temporary access to a non-core DocuSign system used for sending service-related email announcements. The compromise enabled theft of customer and user email addresses but did not extend to names, physical addresses, passwords, Social Security numbers, credit card data, or customer document content. DocuSign confirmed its core eSignature service, envelopes, and document repositories remained secure throughout the incident.

Cyber Incident Image

Following forensic analysis, DocuSign alerted customers that the stolen email addresses facilitated highly targeted phishing attempts, exploiting trust in expected DocuSign communications. The company advised recipients to scrutinize emails for anomalies such as unrecognized senders, unexpected documents, misspellings (e.g., “docusgn.com” or “@docus.com”), attachments, or links deviating from legitimate docusign.com or docusign.net domains. It recommended forwarding suspicious emails to [email protected] before deletion and emphasized that authentic DocuSign emails never require opening PDFs, Office files, or ZIP archives. Users expecting documents were instructed to bypass email links entirely, instead accessing materials directly via docusign.com using unique security codes embedded in legitimate correspondence. The breach amplified existing phishing risks for DocuSign’s 100 million users, as attackers leveraged validated email lists to enhance credibility, ensuring prolonged exploitation potential.

Sources
Sources available to members
1 source