DocuSign & E-Signature Phishing Scams
A fake "you have a document to review and sign" email or text impersonates DocuSign, Adobe Sign, or a similar service. Urgency and a spoofed brand steer you toward a lookalike login page or a malicious file, where the real target is your password, your 2FA code, or a foothold in your inbox.
Last reviewed: 24 July 2026
What this scam is
A DocuSign or e-signature phishing scam is a message that imitates a trusted electronic-signature service — DocuSign and Adobe Sign are the most impersonated brands — to make you believe a real document is waiting for your review and signature. The lure is ordinary and expected: a contract, an invoice, a payslip, an NDA, a package-release form, a payment authorisation. The message carries the service's logo, colours, and layout, and a prominent "Review Document" button. That button rarely opens a real signing session. It leads either to a lookalike login page built to harvest your email address, password, and two-factor code, or to a malicious attachment or file download. A distinct and more dangerous variant abuses the real service: the attacker sends a genuine, correctly branded envelope through an actual e-signature account, and the fraud hides inside the document as a link that jumps out to a phishing site once opened. The distinction that matters most is that the crime is seldom the signature itself — it is the login page or the outbound link sitting behind it.
How it works
The bait is a notification email or text: a familiar brand, a document title chosen to fit your role, and pressure framed as a deadline — a contract that expires today, an overdue invoice, a form that must be signed to release a payment or delivery. Clicking the button opens a page that mimics the service's sign-in screen. You enter your email and password; the page then asks for your two-factor code, which the attacker can relay to the genuine service in real time to seize the session. With your mailbox open, they read your contacts and threads and send the same fake envelope onward — business email compromise — so the next wave arrives from a real, trusted colleague. Other variants skip the login page: the button downloads a malicious file, or the message embeds a real e-signature envelope whose document links out to the phishing site, letting it pass brand filters. Finance and executive staff are prized, because a captured inbox can redirect an invoice or approve a fraudulent wire.
Why this scam works
E-signature requests are woven into ordinary work, so a signing notification triggers no alarm — people click these several times a week without thinking. The impersonated brands are trusted precisely because they handle contracts and money, and their real notification emails look almost identical to the fakes. Urgency is supplied by context that feels legitimate: contracts genuinely do have deadlines and invoices genuinely do fall overdue, so pressure reads as normal business rather than manipulation. The envelope-abuse variant is stronger still, because the email really did come from the real service and survives brand and spam checks. And once one inbox is captured, the follow-on messages arrive from a known, trusted sender, which disarms the scepticism a stranger would face.
Common red flags
- A signing request you were not expecting, or from someone with no reason to send you one
- A button link that resolves to a domain other than the real service's own site
- Urgency in the message — a contract expiring, an invoice overdue, a payment or package waiting to be released
- A page that asks for your email password rather than only your e-signature account credentials
- Small oddities in wording, sender address, or logos despite convincing overall branding
- A signed document whose only real content is a link telling you to view the file elsewhere
- A follow-up wave of identical requests forwarded from a colleague's real address
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
DocuSign: You have a document to review and sign. 'Q3 Vendor Contract' expires in 24 hours. REVIEW DOCUMENT
Adobe Sign — Invoice #4471 is overdue. Please review and sign to avoid service interruption.
A document requires your signature to release your pending delivery. Sign here to confirm your address.
Hi — sending over the signed NDA from earlier, just need you to countersign. Open the envelope and log in to complete.
How to verify before you act
Never sign in through a link in a signing notification — that link is where the whole scam lives. If you genuinely expect a document, open a new browser tab, go to the service's official website yourself, and log in there; a real envelope will be waiting in your account. Check who the document is supposedly from: a signing request from someone with no reason to send you one is a red flag, even if the branding is perfect. Hover over the button or long-press the link and read the actual destination — genuine requests resolve to the service's own domain, not a lookalike or an unrelated site. Be wary of any request that pushes you to hurry, or that asks for your email password rather than only your e-signature account. When in doubt, confirm with the named sender through a channel you already trust, not by replying to the message.
Payment methods used
- No upfront payment (credential theft)
- Bank transfer (via redirected invoices)
- Wire transfer (via business email compromise)
Who is usually targeted
- Office and finance staff
- Business executives
- Anyone expecting a contract or invoice
What to do immediately
- If you entered your password, change it now on the real site, and change it anywhere else you reused it
- Sign out all active sessions and turn on or reset multi-factor authentication on your email and e-signature accounts
- Check your mailbox for rules or forwarding the attacker may have added to hide replies, and remove them
- Warn your contacts and, in a business, your IT or security team — the captured inbox is used to phish others
- Report the message to your email provider and to your national fraud or cybercrime service
- If any invoice, wire, or bank-detail change was actioned, contact your bank or card provider immediately to try to stop it
How to prevent it
- Never log in through a link in a signing email or text — open the service's official site yourself and check for the document there
- Turn on phishing-resistant multi-factor authentication (an authenticator app or hardware key) for your email and e-signature accounts
- Confirm unexpected signing requests with the named sender through a channel you already trust, before opening anything
- Hover over or long-press the button and read the real destination domain before you click
- Treat any page asking for your email password during a signing flow as a scam — a genuine e-sign request never needs it
- In a business, enforce out-of-band verification for any invoice, payment, or bank-detail change that arrives via a signed document
Evidence to preserve
- The original email or text, with full headers and the sender address
- The exact link or button destination and any lookalike login-page URL and screenshots
- Any downloaded attachment, kept isolated, and a record of your account login and security-alert history
- Payment or invoice records if funds or bank details were affected
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
How can I tell a real DocuSign or Adobe Sign email from a fake one?
You often cannot tell from the email alone — the branding, layout, and even the sender can be convincingly spoofed, and one variant is sent through the real service. So do not judge the email; judge the link. Never sign in through the button. Instead, open a new tab, go to the service's official website yourself, and log in. A genuine document will be in your account. If nothing is waiting there, the message was a fake, no matter how real it looked.
I clicked the link and entered my password. What should I do now?
Act quickly. Change that password on the real site immediately, and change it anywhere you reused the same one, since attackers try stolen passwords across accounts. Turn on or reset multi-factor authentication, and sign out all sessions. Check your email settings for forwarding rules or filters the attacker may have added to intercept replies. Then warn your contacts and, at work, your IT team — a captured inbox is used to phish the people who trust you. Report it to your national fraud service.
Why do scammers use e-signature brands instead of just sending a normal phishing email?
Because e-signature requests are trusted and routine. People sign documents through these services all the time, so a signing notification feels like ordinary work rather than a threat, and it slips past the scepticism a random link would face. The brands also handle contracts and money, which makes urgency believable. Most powerfully, attackers can sometimes send the lure through a real e-signature account, so the email genuinely comes from the trusted service and passes the security filters that would block an obvious fake.