Fraud Alert: Phishing Scams Exploiting Account Activation & Billing Notifications
08/06/2026
Docusign has identified a phishing scam where attackers send a large volume of phishing emails that combine Docusign-branded account activation templates with fake billing notifications (such as unauthorized PayPal charges) and fraudulent customer support phone numbers.
The goal is to trick recipients into calling a fraudulent customer support number to steal personal and financial information. Though these notifications may originate from the Docusign platform and appear authentic, they are fraudulent, involving fabricated charges and malicious activity. Our team is actively working to mitigate this type of abuse and disrupt these malicious campaigns.
Examples to look for:
Subject Line: "Account Activation"
Message Content / Key Indicators: References to unexpected purchase details, fake PayPal charges, and request to call a phone number for support or charge disputes.
How to Protect Yourself:
Scrutinize the Sender and Content: Be cautious of unexpected emails, even if they appear to originate from Docusign platform domains. Be highly suspicious if the message references an unfamiliar invoice, purchase confirmation, or an account activation request you did not initiate.
Verify Independently: If you receive an unexpected invoice or payment confirmation, do not click on any links, buttons (such as "Activate"), or call any phone numbers provided within the email. Instead, go directly to the official vendor or source (in this case, PayPal) using a separate, secure connection to verify the request.
Access Documents Safely: Safely access a document by going directly to docusign.com and using the Access Documents feature with the unique Security Code provided at the bottom of the email.
Report Suspicious Activity: If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse feature or Report Abuse Form.