Fraud Alert: Phishing Scams Using Fake Blurred Documents to Gain Device Access
08/20/2026
Docusign has identified an on-platform phishing campaign where attackers use registered Docusign accounts to send envelopes with legitimate-looking documents designed to trick recipients into granting attackers access to recipients' devices and personal information. When recipients open these envelopes, they are presented with a document that appears as a blurred image with a call to action to unblur the image. Clicking this call to action within the document leads to a malicious website that asks the recipient to download a file to “unblur” the image. Downloading this malicious file may grant attackers access to the device and all stored data, including personal information.
While these notifications originate from the Docusign platform and appear authentic, these requests are not legitimate. Our team is actively working to shut down these phishing campaigns to keep your information safe.
Key Indicators to look for:
Blurred Previews: The envelope contains a blurred image and a link or button claiming to "unblur" or "view" the document.
External Prompts: Messaging that mimics Adobe Acrobat or other software, asking you to download tools to access the content.
How to Protect Yourself:
Avoid Suspicious Downloads: Docusign will never require you to download software or "unblurring" tools to view a document. If prompted to do so, stop immediately.
Verify the Sender: If an email is unexpected, contact the sender through a trusted, independent channel (like a known phone number) before interacting with the envelope.
Unsure if a Docusign email is authentic: Do not click on any links. Instead, go directly to docusign.com, click Access Documents at the top of the page, and enter the unique Security Code found at the bottom of the email.
Report Suspicious Activity: If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse feature or Report Abuse Form.