Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

81–90 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#81
post #73

Earlier quoted context omitted.

To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused. Not affiliated, just a happy long-time paying customer. [1] http://33mail.com/rj37w3

I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically

me too. any new email address is

businessname@mydomain.io

Already caught a few selling my info

Re: DocuSign email address database breached and used for phishing campaign

#83

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I strictly started handing out "companyname@mypersonaldomain.tld" as email when interacting with companies. That at least makes routing the inevitable spam to the trash bin slightly easier when a breach occurs. It also provides an indicator of who has (in)voluntarily given away my data.

I've done similar with a catch-all sub-domain for years. It does mean that my mail server sees a lot of junk activity as some email lists out there have many addresses in that sub-domain on them, but at least they are easy to filter out.

Some sites refuse to accept email addresses with more than one "." after the "@" but I figure if they don't understand email addresses I don't want to be trusting them with my details, even throw-away ones, anyway!

Unfortunately I was added to docusign by someone else who gave them my main address...

Re: DocuSign email address database breached and used for phishing campaign

#84

Earlier quoted context omitted.

AliExpress does this, they don't accept "aliexpress@foo.bar". I suppose it's meant to stop you from providing "foo@aliexpress.com", implemented lazily by rejecting anything that contains the substring "aliexpress". Best response I've received when giving an email address of the form "company@mydoma.in" to a representative in person was "oh you work here too?". The concept of catch-all domains is so foreign to most la…

A catchall on my domain was all fun and games till the second dictionary spam run.

I've heard that being a problem, though I've never had that issue using a sub-domain for the catchall (company@sub.domain.tld).

Some sites refuse to accept email addresses with more than one "." after the "@" but figure if they don't understand email addresses I don't want to trust them with my details (even throw-away ones) anyway so go elsewhere.

Re: DocuSign email address database breached and used for phishing campaign

#85
post #67
post #55

Earlier quoted context omitted.

It is coming from the canary birds in the coal mines or in submarines[0]. They have a higher sensibility to CO than humans. This is now part of the common language to say that you sacrifice an animal or "something" to get early warning of something possibly more dangerous. [0]: https://en.wikipedia.org/wiki/Sentinel_species#Historical_ex...

Just wondering, what exactly is being sacrificed in this specific case?

Fake users

Re: DocuSign email address database breached and used for phishing campaign

#86
post #36

Looks like it took them about six days to figure out why their customers were getting spammed. It'd be helpful if they could outline what the "non-core system that allows us to communicate service-related announcements to users via email" actually was. Was this a Mailchimp account that got hacked into or did they have something they managed?

I had the same impression. Pretty sure it was their MailChimp (or similar service) account.

Yeah or an api key leaked

Re: DocuSign email address database breached and used for phishing campaign

#87

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I strictly started handing out "companyname@mypersonaldomain.tld" as email when interacting with companies. That at least makes routing the inevitable spam to the trash bin slightly easier when a breach occurs. It also provides an indicator of who has (in)voluntarily given away my data.

I love their reaction when I say their company name then pause

Re: DocuSign email address database breached and used for phishing campaign

#88

I'm not sure DocuSign has a full handle on what happened here yet. I received six (6) DocuSign emails, half of which used a convincing subject derived from actual DocuSign documents I have signed or processed through the system. Perhaps a coincidence? Or these hackers gained access to more than just "email addresses".

I am skeptical as well. I feel like the standard procedure these days is for a company to acknowledge that their security has been compromised but that the breach was limited to only non-sensitive data.

Re: DocuSign email address database breached and used for phishing campaign

#89
post #31

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I only met docusign in a brief spell and vaguely remember it looked like some kind of borderline scam for enterprise security checklisters. How does clicking a link from an email prove identity? How does it work?

>How does clicking a link from an email prove identity?

Most of these document signing services, as you point out, don't prove identity. They provide a more convenient simulation of the "download, physically sign, scan and return, a pdf document" process. Which doesn't prove identity either.

Personally, I appreciate the shift. It's just as silly, but less cumbersome.

Re: DocuSign email address database breached and used for phishing campaign

#90

Earlier quoted context omitted.

A catchall on my domain was all fun and games till the second dictionary spam run.

I haven't had any issues with that and I've been using a catch all setup for about 7-10 years. Most spam arrives on the actual primary email address.

This was a while back, and I'm guessing that now there are enough gigantic lists of verified emails that the technique lost it's minimal rate of return.

It was a massive headache at the time tho.

Post reply on HN