PayPal Scammers Exploit Docusign API to Trick Customers

Scammers are using Docusign’s Application Programming Interface (API) to send phishing emails that appear legitimate, targeting PayPal users. By creating Docusign accounts and using its templates, fraudsters send fake invoices and alerts about unauthorized transactions, directing victims to call a provided number to “secure” their accounts.

The emails, originating from genuine Docusign accounts, often bypass security filters. However, red flags include the use of Gmail addresses for PayPal customer care and the lack of a signature requirement in the documents.

Docusign states that it investigates and closes suspicious accounts within 24 hours of detection or reporting. Most reported accounts are already flagged by Docusign’s systems, and once closed, all associated documents become inaccessible.

Search for Blogs/Event/News