{
  "slug": "docusign-document-waiting",
  "canonical_name": "DocuSign \"document to review and sign\" phishing",
  "family": "account-suspension",
  "impersonates": {
    "brand": "DocuSign",
    "disclaimer": "DocuSign is not involved; criminals impersonate the brand.",
    "official_fraud_page": "https://www.docusign.com/trust/security/incident-reporting"
  },
  "goal": [
    "credentials",
    "malware"
  ],
  "channels": [
    "email"
  ],
  "summary": "An email that looks like a DocuSign envelope notification with a \"Review document\" button. The button leads to a login page that steals the email password, or to a file download. DocuSign asks for copies at spam@docusign.com.",
  "status": "active",
  "first_seen": null,
  "last_seen": null,
  "recognise": [
    "A document you were not expecting from a sender you do not know",
    "The button asks you to sign in to your email provider first",
    "Real DocuSign emails carry a security code and open on docusign.com"
  ],
  "variants": [],
  "specimen": null,
  "tells": [],
  "indicators": {
    "sender_domains": [],
    "senders": [],
    "reply_to": [],
    "phone_numbers": [],
    "urls": [],
    "wallets": [],
    "attachments": [],
    "note": "Indicators change weekly; an empty list never means an email is safe."
  },
  "what_to_do": {
    "if_received": [
      "Do not click; if you expect a document, open docusign.com and use the security code from the email there",
      "Forward it to spam@docusign.com",
      "Delete it"
    ],
    "if_called_or_paid": [
      "Entered a password? Change it now, and everywhere else you used the same one",
      "Entered card details? Call your bank, ask them to block the card and reissue",
      "Entered a one-time code? Sign in to the real service now and check for changes to email, phone and payment settings"
    ],
    "report_links": [
      {
        "label": "DocuSign: report suspicious emails",
        "url": "https://www.docusign.com/trust/security/incident-reporting"
      },
      {
        "label": "Report to the FTC",
        "url": "https://reportfraud.ftc.gov/"
      }
    ]
  },
  "malware_family": null,
  "timeline": [
    {
      "date": "2026-09-02",
      "type": "registry",
      "title": "Family created",
      "text": "Opened at launch from the pattern DocuSign documents; no dated specimen on record yet — send yours.",
      "added": [],
      "removed": [],
      "sources": []
    }
  ],
  "related": [
    "bec-supplier-bank-change"
  ],
  "sources": [
    "https://www.docusign.com/trust/security/incident-reporting"
  ],
  "legacy_urls": [],
  "legacy_redirect": false,
  "created": "2026-09-02",
  "updated": "2026-09-02",
  "changelog": [
    {
      "date": "2026-09-02",
      "text": "Record created at the registry launch."
    }
  ],
  "url": "https://soft2secure.com/scams/docusign-document-waiting",
  "licence": "CC BY 4.0",
  "generated": "2026-09-03"
}