Fraud alerts
Subscribe using the Docusign Safety Center Alerts RSS feed URL: https://www.docusign.com/trust/safety/feed. Add an RSS reader extension to your browser (Chrome, Firefox), or enable via Outlook on a PC.
Docusign has identified a phishing scam where attackers send a large volume of phishing emails that combine Docusign-branded account activation templates with fake billing notifications (such as unauthorized PayPal charges) and fraudulent customer support phone numbers.
The goal is to trick recipients into calling a fraudulent customer support number to steal personal and financial information. Though these notifications may originate from the Docusign platform and appear authentic, they are fraudulent, involving fabricated charges and malicious activity. Our team is actively working to mitigate this type of abuse and disrupt these malicious campaigns.
Examples to look for:
Subject Line: "Account Activation"
Message Content / Key Indicators: References to unexpected purchase details, fake PayPal charges, and request to call a phone number for support or charge disputes.
How to Protect Yourself:
Scrutinize the Sender and Content: Be cautious of unexpected emails, even if they appear to originate from Docusign platform domains. Be highly suspicious if the message references an unfamiliar invoice, purchase confirmation, or an account activation request you did not initiate.
Verify Independently: If you receive an unexpected invoice or payment confirmation, do not click on any links, buttons (such as "Activate"), or call any phone numbers provided within the email. Instead, go directly to the official vendor or source (in this case, PayPal) using a separate, secure connection to verify the request.
Access Documents Safely: Safely access a document by going directly to docusign.com and using the Access Documents feature with the unique Security Code provided at the bottom of the email.
Report Suspicious Activity: If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse feature or Report Abuse Form.
Docusign has observed a phishing campaign that impersonates Intuit QuickBooks by sending fraudulent Docusign envelopes from look-alike email addresses. These messages prompt recipients to review unexpected invoices or remittance advice, tricking them into clicking malicious links or processing unauthorized financial requests.
While these notifications originate from the Docusign platform and appear authentic, these requests are not legitimate. Our team is actively working to mitigate this type of abuse and disrupt the activity behind these campaigns.
Examples to look for:
Subject Line: Complete with Docusign: Outstanding Remittance Advise & Inv. xslx
Sender Display Name (in message body): Accounts Payable
Sender Email Format (in message body): quickbooks-notification.intuit.com@[random_domain].com
Measures you can take to protect yourself and your data:
Check the Sender and the Message: Be cautious of unexpected emails, even if they appear to originate from Docusign, especially if they involve unexpected invoices, payment updates, or remittance advice.
Check Your Account Directly: If you receive an unexpected invoice or accounting notification, do not click links, scan QR codes, or call numbers listed inside the document or email. Instead, go directly to the official vendor or source (in this case, Intuit QuickBooks) using a separate, secure connection to verify the request.
Verify and Report Suspicious Activity: Safely access a document by going directly to docusign.com and using the Access Documents feature with the unique Security Code provided at the bottom of the email. If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse feature or Report Abuse Form.
Docusign has observed a phishing campaign where attackers impersonate password managers like LastPass by sending fake emails disguised as Docusign notifications. These messages frequently claim that users "have 14 business days to review and accept the updated terms" to create a false sense of urgency. The goal is to trick recipients into visiting fake login pages designed to steal passwords and sensitive credentials.
While these notifications use Docusign branding and appear authentic, they do not originate from Docusign. Our team is actively working to mitigate this abuse and take down malicious sites associated with these campaigns.
Examples to look for:
Urgent Message Text: "have 14 business days to review and accept the updated terms"
Malicious URL/Link Redirect: https[:]//lastpasscompliance[.]com
Measures you can take to protect yourself and your data:
Check the Sender and the Message: Be cautious of unexpected emails, even if they feature Docusign or LastPass branding, especially if they demand you accept updated terms of service or compliance policies under a strict deadline.
Check Your Account Directly: If you receive an unexpected security or compliance notification, do not click links, open attachments, or enter your credentials into external web pages. Instead, go directly to the official vendor website via a separate, secure browser window to verify the request.
Verify and Report Suspicious Activity: Safely access a legitimate Docusign document by going directly to docusign.com and using the Access Documents feature with the unique Security Code. If you receive a suspicious message impersonating Docusign, forward it as an attachment to verify@docusign.com.
Attackers are using sophisticated phishing campaigns to impersonate financial institutions by sending fraudulent Docusign envelopes for purported payment bonus and disbursement confirmations. The goal is to solicit user engagement by leveraging a combination of QR codes and links to credential harvesting sites to steal login credentials. While these notifications originate from the Docusign platform and appear authentic, this activity is a malicious third-party exploitation of our services.
Our team is actively working to mitigate this type of abuse, including working to take down malicious sites used in these campaigns.
Here are examples of email subject lines:
Payment_Advice
Payment_Confirmation_Receipt
Payment_Disbursement
Transfer_Confirmation_Notice
Vendor Contract PayApp Ref# [REFERENCE NUMBER]
[FINANCIAL INSTITUTION]_authorization_[REFERENCE NUMBER]_enclosed.pdf
Here are some measures you can take to protect yourself and your data:
Check the sender and the message: Be cautious of unexpected emails, even if they look like they are from Docusign, especially if they are regarding an unexpected payment or disbursement.
Check Your Account Directly: If you receive an unexpected notification from a financial institution, do not click links, scan QR codes, or call numbers in the envelope/email. Scammers use these to trick you. Instead, go directly to the official source (e.g., your bank or financial institution) using a separate, secure connection to verify the payment or disbursement. A legitimate financial company will never ask you to transfer funds over the phone to "secure" assets.
Verify and Report Suspicious Activity: Safely access a document by going directly to docusign.com and using the Access Documents feature with the unique Security Code. If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse Feature or Report Abuse Form.
We have identified and mitigated a scam where attackers misused legitimate Docusign system features, such as "Send Report", to bypass email filters. We have taken direct action to prevent this specific abuse and remain vigilant as attackers continue to evolve their tactics.
Because these notifications originate from official Docusign servers, they appear highly authentic. Attackers use urgent calls to action, such as cryptocurrency-themed unauthorized transaction alerts or security alerts, to provoke a call to a fake number listed in the email in an attempt to steal personal and financial information.
Here are examples of email subject lines:
Fraud transaction detected on your account BTC Call [PHONE NUMBER] Authority.
Critical Security Alert: Order confirmed. Microsoft Office Subscription. Call: [PHONE NUMBER]
Fraud Warning: Your account reflects a 0.026 BTC transaction. For help contact: [PHONE NUMBER]
Here are some measures you can take to protect yourself and your data:
Check the sender and the message: Be cautious of unexpected emails, even if they look like they are from Docusign, especially if they warn you about fraud or unauthorized transactions. Official Docusign workflow notifications will never include links that demand immediate action, such as requiring you to log in or provide a signature.
Check Your Account Directly: If you receive a “callback” email, do not click links or call numbers in the email. Scammers use these to trick you. Instead, go directly to the official source (e.g. crypto platform or wallet) using a separate, secure connection to check your account. A legitimate financial company will never ask you to transfer funds over the phone to "secure" assets.
Look for Red Flags: Be cautious of emails that demand immediate action, use generic greetings, or contain minor misspellings or poor grammar.
Report Suspicious Activity: If a Docusign notification seems like a scam or you're unsure of its authenticity, please report it immediately using one of these options:
Use the Docusign Report Abuse feature directly.
Submit a report directly to Docusign using our Report Abuse Webform.
We have observed attackers executing sophisticated phishing scams that use a combination of workflow notifications from Docusign Maestro and external communication. The goal appears to be to trick recipients into believing they have an unexpected invoice or subscription renewal from a trusted corporation (such as Microsoft) and lead them to contact a fake support number to steal personal and financial information.
Here are some example subject lines:
Your subscription remains active– Microsoft
Your Microsoft Purchase Confirmation
How can I protect myself from these phishing attempts?
Scrutinize the Sender and Content: Even if an email appears to come from a trusted domain like Docusign, be highly suspicious if the content involves an unexpected invoice or an unfamiliar subscription. Legitimate notifications from Docusign workflows will never contain a link to log into your account or for further action like a signature.
Verify Independently: If you receive an unexpected invoice or purchase confirmation, do not click on any links or call any phone numbers provided in the email. Instead, independently navigate to the official website or service portal for the purported sender (e.g., Microsoft's official site) to check your subscription status or billing history.
Look for Red Flags: Be wary of emails demanding immediate action, using generic greetings, or containing slight misspellings or poor grammar.
Report Suspicious Activity: If you suspect a notification is a scam or are unsure of its authenticity, report it immediately through one of the following methods:
Use the Report Abuse feature directly.
Submit a report via our Report Abuse Webform.
We have recently observed reports of fraudulent emails that impersonate seasonal notifications from trusted brands, including Docusign. This activity is a form of external brand impersonation where scammers use seasonal themes, such as gift orders (e.g., wine deliveries) or year-end and year-start documents (e.g., related to benefits enrollment, tax forms, policy updates), to create a false sense of urgency.
Identify the risk
The goal of these emails is to trick you into clicking malicious links. These links may redirect you through multiple websites to a fake login page designed to steal your credentials or personal information.
What to look for
Inconsistent branding: Scammers may use a mix of current and legacy branding (e.g., the older DocuSign with a capital S). Watch for outdated logos, mismatched fonts, or formatting errors.
Suspicious senders: Always check the sender’s email address. Official notifications will only come from @docusign.com or @docusign.net. Exercise caution with any email claiming to be from Docusign that originates from an unofficial domain. Regardless of the sender, you should always be cautious of domains you do not recognize.
Unexpected content: Remain vigilant regarding any documents or signature requests you were not anticipating, and treat unsolicited emails with skepticism — even from a sender you believe you recognize. If you are in doubt, avoid interacting with the email and instead confirm the request is legitimate by contacting the sender through a verified phone number or a known, trusted email address.
Recommended action
Do not click: Avoid interacting with buttons or links in any unexpected suspicious email.
Verify independently: To safely access a document, go directly to docusign.com and enter the unique Security Code found at the bottom of the email using the Access Documents feature.
Report: If you receive a suspicious message, forward it as an attachment to verify@docusign.com for analysis. We will quickly provide confirmation indicating whether the content is legitimate or contains suspicious material, along with recommended next steps you should take. For business users, we also recommend reporting the incident to your security or IT department to ensure your organization is aware and can take any additional necessary precautions.
We're seeing an increase in sophisticated phishing scams that involve both internal and external activity. These scams use the platform itself in combination with communication or actions that take place outside our system. This hybrid method uses an external email forwarding service to send malicious envelopes to large lists of recipients, making the emails appear to come directly from Docusign.
A common tactic is a fake invoice from a well-known company like Norton, PayPal, or Geek Squad. The scammer sends a fraudulent document that looks like it's from a legitimate source and asks you to call a phone number to resolve an issue. The goal is to trick you into giving away your bank or credit card information. Sometimes the email will even say the document has already been signed to pressure you into acting quickly.
Here are some examples of subject lines these scams might use:
Order completed successfully
Completed: Transaction Details 423
Purchase has been completed @ Sep 04, 2025
Security Notice: Refund Hold Needs Immediate Action with Your Authorization
Review needed: recent Primary account activity 💯 with Docusign: AH06dq76TXhc28Gw
What should I do if I receive one of these?
Do not click on any links in the email or attachments.
Do not call the phone number in the email.
Do not share any personal or financial information.
Report the suspicious email immediately through our Report Abuse feature or directly through our Report Abuse Webform.
We've recently seen an increase in phishing scams where fraudsters pretend to be from Human Resources and Payroll Departments, or even government offices. Their goal is to trick you into taking action.
These scam emails often contain a malicious QR code that, when scanned, leads to a fake login page. The envelope itself may also contain another fraudulent QR code or a link taking you to an external site intended to steal sensitive information, which may include financial data, personal data or login details (username and password). This tactic is known as “quishing”.
Examples of subject lines to look out for:
EFT/ACH Remittance Information
Remittance Advice
What should I do if I get one of these?
Do not scan any QR codes or click on any links.
Do not enter your username or password on a page you reached from an email or QR code.
Do not click on any email or attachment links.
Report the suspicious email immediately through our Report Abuse feature or directly through our Report Abuse Webform.
We have observed a concerning increase in phishing campaigns where fraudsters impersonate government offices, municipalities, and Procurement Departments. These attacks are designed to trick you into providing personal and financial information.
A common tactic is the use of a fraudulent envelope document that contains a malicious QR code. When scanned, this QR code directs you to a fake website designed to steal your login credentials, bank details, or other sensitive information. This tactic is known as “quishing”.
Examples of subject lines to look out for:
Complete with Docusign: City of San Francisco.pdf
Complete with Docusign: City Of Tampa.pdf
Complete with Docusign: LACity Purchasing Contract #W9125EK21D0006.pdf
Your City of Chicago News & Resources – September 2025.pdf - Please Review
What should I do if I get one of these?
Do not scan any QR codes or click on any links.
Do not enter your username or password on a page reached via a link or QR code from an unsolicited email.
Do not click on any email or attachment links.
Report the suspicious email immediately through our Report Abuse feature or directly through our Report Abuse Webform.
Verify any official communication by navigating directly to the government agency's official website.