Your company is participating in a Cyber Security Education Program.
This Docusign Phishing Attack included the following social engineering techniques:
- Spoofed email and domain (example: docusign@bc-en.ca).
- Urgency to act (example: Document for review and sign).
- Simple clean email to minimize suspicion.
- Link/Button to allow you take action attacker wants.
- Verbiage to catch attention (example: REVIEW DOCUMENT).
How to spot this was a phishing email:
- Was this an email you expected to receive? No - Be cautious
- There is no distinguishing or customization (from, to, or document information).
- The sender named email address was not associated with Docusign.
- Example: docusign@... is not the primary domain (bc-en.ca is primary domain and not associated with Docusign.
- The link provided used suspicious domain similar to above..