< Back to all clusters
[TECHNOLOGY] · Panama, Singapore · 3 sources

started · updated

Kaspersky detects phishing campaign impersonating Zoom and DocuSign

Kaspersky has identified an active phishing campaign targeting corporate accounts by impersonating official communications from Zoom and DocuSign. As of September 11, more than 1,000 malicious emails have been detected.

The attack has proceeded in two waves. The initial wave utilized DocuSign impersonations to direct users to fraudulent links for credential theft. The second wave involves Zoom-themed notifications that falsely warn users their accounts are about to be disabled, creating a sense of urgency. These messages use both phishing links and embedded forms to solicit personal information and credit card details.

The campaign has impacted various regions, including Latin America, the Middle East, Western Europe, Russia, Armenia, and Azerbaijan. Security experts note that while advanced AI-driven threats receive significant attention, these low-tech impersonation tactics remain highly effective because employees may overlook signs of fraud amidst high email volumes. Compromised corporate accounts pose a significant risk, as attackers can access sensitive data, impersonate users, and move laterally within an organization.

Entities

DocuSign · Kaspersky · Zoom