
Cybercriminals are exploiting DocuSign's Envelope API to send fraudulent invoices and payment requests, leading to Business Email Compromise attacks. By gaining access to DocuSign's API, attackers create documents that appear to be genuine invoices, which victims e-sign. The attackers then use these signed documents to convince corporate billing departments to authorize unauthorized payments. Despite DocuSign not offering invoicing or payment capabilities, hackers are utilizing the company's own API to facilitate these scams, effectively turning DocuSign's services against its users. Security experts advise users to be cautious when using DocuSign, as the platform's API exploitation presents new risks for businesses.

Gmail Users Beware—Link Hovering Attacks On The Up https://t.co/sEIQLDhe4l https://t.co/QnxYLGZhHU
Alert For Lawyers: Don’t Fall For This Federal Courts Phishing Scam https://t.co/Nx2fcRfXvW
Phishing emails purported to be from PACER’s electronic filing system target lawyers. https://t.co/6asJCPmGlp #cybersecurity