< Back to all clusters
[TECHNOLOGY] · Azerbaijan, Türkiye, Russia, Armenia · 3 sources

started · updated

Kaspersky uncovers phishing campaign impersonating Zoom and DocuSign

Kaspersky has uncovered a widespread phishing campaign that impersonates official communications from Zoom and DocuSign. The attack utilizes traditional but effective tactics to deceive users and steal sensitive information.

The first wave of the campaign targeted corporate accounts across the Middle East, Latin America, Western Europe, Russia, Armenia, and Azerbaijan using fraudulent DocuSign messages. These emails contained malicious links designed to steal corporate credentials.

A second wave followed, impersonating Zoom notifications. These messages created a sense of urgency by claiming user accounts were about to be suspended. Attackers employed two primary methods: redirecting victims to fake phishing pages and using embedded forms to collect personal data and credit card information. As of September 2026, over one thousand phishing emails related to this campaign have been detected.

Entities

Andrey Kovtun · DocuSign · Kaspersky · Zoom