Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

21–30 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#21

Earlier quoted context omitted.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

Are you sure? I don't know how credit card companies in the US behave, but here in the Netherlands I called up mastercard to ask them whether I am liable for any fraud that occurs if I do something like this (or send credit card info over email, like so many hotels want). The credit card company tells me, yes I am liable for any fraud that occurs, because email and unecrypted text boxes on websites are known to be in…

In AUS it's much like chatmasta says: if its a CC linked a true "credit" account the issuer has the value entirely underwritten. If you can reasonably prove that someone stole it for example, then you'll get your money [credit] back.

If it's linked to a savings account and it's a Visa/MC debit card, for example, then it's a different story. The funds are not insured and so if you loose it it's on you.

Re: DocuSign email address database breached and used for phishing campaign

#23
post #7

Earlier quoted context omitted.

Sure they're different but make no mistake: emails being breached are a big deal! This is an appropriate response https://twitter.com/troyhunt/status/864315287092342785

I fail to see how slightly wider dissemination of a bit of info I post publicly on my profile at this very web site constitutes a privacy or security risk to me.

Then let's hope you're a phishing detection skills are up to par then.

Re: DocuSign email address database breached and used for phishing campaign

#24
>The emails “spoofed” the DocuSign brand in an attempt to trick recipients into opening an attached Word document that, when clicked, installs malicious software.

I love how nothing changed about this malware payload delivery in about 2 decades.

Re: DocuSign email address database breached and used for phishing campaign

#25
post #7

Earlier quoted context omitted.

Sure they're different but make no mistake: emails being breached are a big deal! This is an appropriate response https://twitter.com/troyhunt/status/864315287092342785

I fail to see how slightly wider dissemination of a bit of info I post publicly on my profile at this very web site constitutes a privacy or security risk to me.

Maybe you have a relative or loved one who doesn't get much spam or phishing?

Re: DocuSign email address database breached and used for phishing campaign

#26
post #10
post #9

Earlier quoted context omitted.

As troy hunt himself wrote... https://www.troyhunt.com/im-sorry-but-your-email-address-is-... This is annoying but not a big deal or a privacy breach, DocuSign is so prevalent your email being in there means basically nothing.

Disagree https://www.troyhunt.com/im-sorry-but-your-email-address-is-...

This incorrectly assumes it's much more valuable to only spam people with access to a service than just a list of people, and I doubt that holds in practice

Re: DocuSign email address database breached and used for phishing campaign

#27

Earlier quoted context omitted.

Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

I recently had to do this (my gym had a data breach), it took over 3 months to get my money back and god knows how many hours and phone calls.

Re: DocuSign email address database breached and used for phishing campaign

#29

Earlier quoted context omitted.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

Are you sure? I don't know how credit card companies in the US behave, but here in the Netherlands I called up mastercard to ask them whether I am liable for any fraud that occurs if I do something like this (or send credit card info over email, like so many hotels want). The credit card company tells me, yes I am liable for any fraud that occurs, because email and unecrypted text boxes on websites are known to be in…

Even if the credit card company decides to hold you liable, you're still better off, because they have to follow court procedures and get a judgment against you before they can actually take your money.

With a debit card, the money is just gone and the burden is generally on you to find some way of recovering it from whoever stole it.

Re: DocuSign email address database breached and used for phishing campaign

#30

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I strictly started handing out "companyname@mypersonaldomain.tld" as email when interacting with companies. That at least makes routing the inevitable spam to the trash bin slightly easier when a breach occurs. It also provides an indicator of who has (in)voluntarily given away my data.
Post reply on HN