Cyber criminals have found new ways to exploit the DocuSign API to deliver fraudulent invoices that appear authentic.
These schemes leverage legitimate DocuSign accounts and official templates, making detection more challenging.
The attackers set up paid DocuSign accounts, customize templates, and use brand-specific details to create fake invoices.
Organizations need to enhance security measures, verify sender credentials, implement internal approval procedures, provide awareness training, monitor for anomalies, and follow best practices to protect against these attacks.