Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

51–60 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#52
post #50

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.

Apologies, you're right, it's not really covered as it's a bit of a niche industry term. It relates back to the days of coal mines, and the birds being used as an early warning system - https://en.m.wiktionary.org/wiki/canary_in_a_coal_mine

Re: DocuSign email address database breached and used for phishing campaign

#53
post #50

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.

Canaries were used in mines to signal pockets of unbreathable gas; they would die before the humans giving them an opportunity to escape.

Canary has developed into a standard term for warnings which are detecting the danger allowing mitigation as opposed to predicting the danger which would allow avoidance.

Re: DocuSign email address database breached and used for phishing campaign

#54
post #50

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.

It's a reference to the canaries that were used in coal mines to detect carbon monoxide. Since then 'canary' has been used to refer to early warning systems.

https://en.wikipedia.org/wiki/Sentinel_species

Re: DocuSign email address database breached and used for phishing campaign

#55
post #50

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.

It is coming from the canary birds in the coal mines or in submarines[0]. They have a higher sensibility to CO than humans. This is now part of the common language to say that you sacrifice an animal or "something" to get early warning of something possibly more dangerous.

[0]: https://en.wikipedia.org/wiki/Sentinel_species#Historical_ex...

Re: DocuSign email address database breached and used for phishing campaign

#57
post #7

Earlier quoted context omitted.

Sure they're different but make no mistake: emails being breached are a big deal! This is an appropriate response https://twitter.com/troyhunt/status/864315287092342785

I fail to see how slightly wider dissemination of a bit of info I post publicly on my profile at this very web site constitutes a privacy or security risk to me.

Well, that is you. Others just might be quite a bit more careful. Or is that inconceivable for you?

Re: DocuSign email address database breached and used for phishing campaign

#58
post #42

Earlier quoted context omitted.

I've been doing this for awhile. It's especially interesting when giving it to a representative in person, some people will refuse to enter it in their systems. I've also had one webform reject it outright. Lately I've started just using random words to get around this awkwardness and make my pattern less predictable. When I get the first email from that company (often happens within minutes) I just give it the actua…

AliExpress does this, they don't accept "aliexpress@foo.bar". I suppose it's meant to stop you from providing "foo@aliexpress.com", implemented lazily by rejecting anything that contains the substring "aliexpress". Best response I've received when giving an email address of the form "company@mydoma.in" to a representative in person was "oh you work here too?". The concept of catch-all domains is so foreign to most la…

>>> I suppose it's meant to stop you from providing "foo@aliexpress.com", implemented lazily by rejecting anything that contains the substring "aliexpress".

Most likely it is to stop you from making an address with "aliexpress" in it, so you don't look like affiliated to aliexpress in any way (think: phishing).

Re: DocuSign email address database breached and used for phishing campaign

#59

I'm not sure DocuSign has a full handle on what happened here yet. I received six (6) DocuSign emails, half of which used a convincing subject derived from actual DocuSign documents I have signed or processed through the system. Perhaps a coincidence? Or these hackers gained access to more than just "email addresses".

Hmmm yes I have received a few and if I recall, some of them had titles very similar to docusign documents I was previously sent. Exact titles similar to this: "Accounting Invoice 630761 Document Ready for Signature"

The postmortem states that the phishing campaign used only a few patterns.

"Delete any emails with the subject line, “Completed: [domain name] – Wire transfer for recipient-name Document Ready for Signature” and “Completed [domain name/email address] – Accounting Invoice [Number] Document Ready for Signature”. These emails are not from DocuSign. They were sent by a malicious third party and contain a link to malware spam."

Did you received phishing with other subjects?

Re: DocuSign email address database breached and used for phishing campaign

#60

Earlier quoted context omitted.

Are you sure? I don't know how credit card companies in the US behave, but here in the Netherlands I called up mastercard to ask them whether I am liable for any fraud that occurs if I do something like this (or send credit card info over email, like so many hotels want). The credit card company tells me, yes I am liable for any fraud that occurs, because email and unecrypted text boxes on websites are known to be in…

Even if the credit card company decides to hold you liable, you're still better off, because they have to follow court procedures and get a judgment against you before they can actually take your money. With a debit card, the money is just gone and the burden is generally on you to find some way of recovering it from whoever stole it.

>>> With a debit card, the money is just gone and the burden is generally on you to find some way of recovering it from whoever stole it.

Not true. Not in Europe.

Post reply on HN