DocuSign is a company that provides technology for the transmission of contracts and other documents with features for electronic signatures.  DocuSign is used by many businesses.  Recently I received a phishing email, reproduced below that purported to be sent by my landlord in regard to a change in the terms of my lease that required my immediate attention.  This phishing email prompts me  to click on a link to open a document that needed my signature.  The phishing email looked very professional and contained the DocuSign logo and appeared legitimate.  However, the email address of the sender was one totally unrelated to either DocuSign or anyone I do business with.  Most likely it was the email address of someone whose email account had been hacked and made a part of a botnet used by the cybercriminal to send out large numbers of these emails.  Additionally, I do not rent any real estate so the email couldn’t apply to me.  Scammers send these emails out in large numbers hoping that many people who do rent their homes will be lured into clicking on the link

This phishing email was designed to lure the person receiving the email to click on the link and either provide personal information that could be used for identity theft, or, as more likely in this particular phishing attempt, merely by clicking on the link would have downloaded malware such as ransomware or keystroke logging malware into the computer of the person clicking on the link.  Keystroke logging malware would have enabled the cybercriminal to steal all of the personal information from the computer and make that person a victim of identity theft.   I removed the link from the email displayed below.

DοcuSiցn

The landlord sent you a document for consideration and signing.
Your lease contract requires attention

New conditions and details can be found in the attached file

Please Dοcu Siցn 9322503126_05202021.zip

Thank You

Do Not Share This Email
This email contains an attached document that can be opened by downloading it to your computer. Office software is required to operate correctly. Please do not share this attachment with others.About our company
Sign contracts electronically in a moment. It’s legally binding. Our company provides a professional solution for signing documents online.Email identifier
XK9SRrxJqpdFOlkmBJtbj3QwsBcvWi2xK
kkFM7EeHdsC15bURHR5BFJumGEhq8JB68EDGBOMHSejkMq6
rIxhThis message was sent to you by the landlord who is using our service. If you would rather not receive email from this sender you may contact the sender with your request.

TIPS

In this case, I actually followed my own advice as to never click on a link regardless of how legitimate the email or text message may appear until confirming that the message is legitimate.  In this case I didn’t even need to confirm that it was not legitimate because of the telltale evidence of the email address of the sender and the fact that I do not have any leases.

The lesson here is clear.  You can never be sure when you receive an email as to who is really contacting you.  Although sometimes it is obvious when the email address of the sender does not correspond to who is represented as sending the email, but other times  the email account of someone or some company you trust could have been hacked and used to send you the malware. Therefore you should never click on a link or download an attachment in an email until you have absolutely and independently confirmed that it is legitimate.

For those of you receiving the Scam of the day through an email, I just want to remind you that if you want to see the ever increasing list of Coronavirus scams go to the first page of the http://www.scamicide.com website and click on the tab at the top of the page that indicates “Coronavirus Scams.”  Scamicide has been cited by the New York Times as one of three top sources for information about Coronavirus related scams.

If you are not a subscriber to Scamicide.com and would like to receive daily emails with the Scam of the day, all you need to do is sign up for free using this link. https://scamicide.com/scam-of-the-day/