HomeSecurityHackers send fake invoices via DocuSign's Envelopes API

Hackers send fake invoices via DocuSign's Envelopes API

Hackers are abusing the DocuSign Envelopes API to create and mass-distribute fake invoices that look genuine, impersonating well-known brands like Norton and PayPal.

See also: Chinese hackers Evasive Panda target Taiwan with CloudScout toolset

DocuSign Envelopes API

By using a legitimate service, the attackers bypass email security protections by originating from a real DocuSign domain, docusign.net.

The goal is for their victims to electronically sign documents, which they can then use to authorize payments independently of the company's billing departments.

DocuSign is an e-signature platform that enables the digital signing, sending, and management of documents. The Envelopes API is a core component of eSignature REST API , which allows developers to create, send, and manage document envelopes that define the signing process.

The API is intended to help customers automate the sending of documents that need signing, track their status, and retrieve them when signed.

See also: Canadian Cyber ​​Center warns that Chinese hackers are scanning IT systems

According to security researchers at Wallarm , malicious actors using legitimate paid DocuSign accounts are abusing the Envelopes API to send fake invoices that mimic the look and feel of trusted software companies.

Hackers send fake invoices via DocuSign's Envelopes API

These users have full access to the platform’s templates, allowing them to design branded documents that impersonate the entity. They then use the “Envelopes:create” API function to create and send large volumes of fake invoices to multiple potential victims.

Wallarm says the fees shown on these invoices are kept within a realistic range to increase the sense of legitimacy of the signature request. She notes that this type of abuse of the Envelopes API, which she has reported to DocuSign, has been going on for some time, and customers have reported the campaigns multiple times on the platform’s community forums.

See also: Iranian hackers sell access to critical infrastructure as brokers

In today’s digital age, email security protections are paramount to protecting sensitive information from cyber threats .Implementing strong passwords is the foundation of email security, as complex combinations of letters, numbers, and symbols can significantly reduce the risk of unauthorized access. Multi-factor authentication (MFA) adds an extra layer of security by requiring users to verify their identity through a second method, such as a mobile app or SMS code. Email encryption ensures that messages and attachments are only accessible to intended recipients, rendering intercepted data useless to hackers. Being aware of phishing scams and regularly updating passwords and security software are also crucial practices for maintaining strong email security.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS