Fraud Alert: Credential Harvesting Scam Impersonating LastPass
07/23/2026
Docusign has observed a phishing campaign where attackers impersonate password managers like LastPass by sending fake emails disguised as Docusign notifications. These messages frequently claim that users "have 14 business days to review and accept the updated terms" to create a false sense of urgency. The goal is to trick recipients into visiting fake login pages designed to steal passwords and sensitive credentials.
While these notifications use Docusign branding and appear authentic, they do not originate from Docusign. Our team is actively working to mitigate this abuse and take down malicious sites associated with these campaigns.
Examples to look for:
Urgent Message Text: "have 14 business days to review and accept the updated terms"
Malicious URL/Link Redirect: https[:]//lastpasscompliance[.]com
Measures you can take to protect yourself and your data:
Check the Sender and the Message: Be cautious of unexpected emails, even if they feature Docusign or LastPass branding, especially if they demand you accept updated terms of service or compliance policies under a strict deadline.
Check Your Account Directly: If you receive an unexpected security or compliance notification, do not click links, open attachments, or enter your credentials into external web pages. Instead, go directly to the official vendor website via a separate, secure browser window to verify the request.
Verify and Report Suspicious Activity: Safely access a legitimate Docusign document by going directly to docusign.com and using the Access Documents feature with the unique Security Code. If you receive a suspicious message impersonating Docusign, forward it as an attachment to verify@docusign.com.