Skip to main content
Trust Center

Fraud Alert: Phishing Campaign Impersonating Intuit QuickBooks

07/23/2026

Docusign has observed a phishing campaign that impersonates Intuit QuickBooks by sending fraudulent Docusign envelopes from look-alike email addresses. These messages prompt recipients to review unexpected invoices or remittance advice, tricking them into clicking malicious links or processing unauthorized financial requests.

While these notifications originate from the Docusign platform and appear authentic, these requests are not legitimate. Our team is actively working to mitigate this type of abuse and disrupt the activity behind these campaigns.

Examples to look for:

  • Subject Line: Complete with Docusign: Outstanding Remittance Advise & Inv. xslx

  • Sender Display Name (in message body): Accounts Payable

  • Sender Email Format (in message body): quickbooks-notification.intuit.com@[random_domain].com

Measures you can take to protect yourself and your data:

  • Check the Sender and the Message: Be cautious of unexpected emails, even if they appear to originate from Docusign, especially if they involve unexpected invoices, payment updates, or remittance advice.

  • Check Your Account Directly: If you receive an unexpected invoice or accounting notification, do not click links, scan QR codes, or call numbers listed inside the document or email. Instead, go directly to the official vendor or source (in this case, Intuit QuickBooks) using a separate, secure connection to verify the request.

  • Verify and Report Suspicious Activity: Safely access a document by going directly to docusign.com and using the Access Documents feature with the unique Security Code provided at the bottom of the email. If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse feature or Report Abuse Form.