Wednesday, August 12, 2026 Digital Forensics & Evidence Sign in
Lars Daniel

Digital forensics expert & expert witness · The Forbes digital forensics columnist

Digital Life & Security

DocuSign Exploit Lets Hackers Send Fake Invoices

By leveraging legitimate DocuSign accounts and API access, threat actors are sending carefully crafted fake invoices directly to targets’ inboxes.

DocuSign headquarters in SOMA district, San Francisco
DocuSign, Inc. is an American company providing document management services. · getty

In a recent cyber threat development discovered by the Wallarm security firm, attackers are exploiting DocuSign’s API capabilities to deliver fake invoices that are bypassing traditional security measures.

By leveraging legitimate DocuSign accounts and API access, threat actors are sending carefully crafted invoices directly to targets’ inboxes, with messages that look convincingly authentic.

How Attackers are Using DocuSign’s API to Evade Detection

DocuSign, a widely used digital platform for managing secure electronic agreements, has inadvertently become a tool for scammers through its API environment.

APIs, or Application Programming Interfaces, allow developers to integrate DocuSign’s services into other applications and automate document workflows. By gaining access to DocuSign’s API, attackers with legitimate accounts can create and send documents that appear to be genuine invoices or payment requests.

This phishing technique is particularly dangerous because of its strategic design:

No Malicious Links or Attachments: Many phishing attempts are detected by email filters looking for suspicious links or attachments. In this scheme, however, attackers send invoices that contain no direct links or attachments—just seemingly legitimate instructions for payment, which makes them harder to flag as suspicious.

Brand Familiarity and Credibility: DocuSign is widely trusted across various industries, including finance, real estate, and healthcare. When recipients see a DocuSign email, they are more likely to trust it without question, especially when the email references known vendors or familiar account details.

Trump Vs. Harris 2024 Polls: Final Forecasts End In A Virtual Tie As Harris Closes Gap

Samsung’s Update Decision—Bad News For Millions Of Galaxy S24 And S23 Owners

Election 2024 Swing State Polls: Trump-Harris Race Deadlocked On Election Eve—As Pennsylvania Still Tied (Updated)

Customization and Impersonation: With DocuSign’s API, attackers can easily customize templates, adding official logos, business names, and invoice formats that look authentic. This level of detail reduces skepticism among recipients, increasing the likelihood of successful payment.

Why This Tactic Is So Effective

This phishing tactic is particularly effective due to its ability to evade detection mechanisms and exploit human trust. Most email security systems are set up to flag obvious phishing markers, such as unrecognized senders or websites with known malware. However, emails coming directly from DocuSign’s platform are marked as legitimate because they are technically coming from a trusted source, effectively bypassing these standard protections.

Furthermore, the emails often impersonate well-known brands or suppliers, creating invoices that appear to come from established businesses. When recipients—often employees in accounts payable or finance departments—receive these invoices, they may recognize the brand but not question the details, especially if they’re busy processing other legitimate invoices.

The absence of an immediate, detectable threat, such as a malicious link, makes the attack particularly insidious, as it relies on users’ trust and familiarity with DocuSign rather than traditional malware tactics.

These non-traditional attacks require more than the traditional phishing training, which is unlikely to cover these more sophisticated techniques. Educating employees—especially those in finance roles—about the risks of fraudulent invoices and how to verify payment requests would be wise for organizations to prioritize in light of novel cyberattacks like this.


This column originally appeared in Forbes.

The newsletter

Digital forensics, explained before you need it

AI evidence, deepfakes and cell phone forensics from an expert witness who works these cases. No hype, no fear-mongering. Free.

Check your inbox to confirm your subscription.