Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

31–40 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#31

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I only met docusign in a brief spell and vaguely remember it looked like some kind of borderline scam for enterprise security checklisters.

How does clicking a link from an email prove identity? How does it work?

Re: DocuSign email address database breached and used for phishing campaign

#32
I'm not sure DocuSign has a full handle on what happened here yet. I received six (6) DocuSign emails, half of which used a convincing subject derived from actual DocuSign documents I have signed or processed through the system. Perhaps a coincidence? Or these hackers gained access to more than just "email addresses".

Re: DocuSign email address database breached and used for phishing campaign

#33

Earlier quoted context omitted.

Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

Whilst technically true, in the United States, the pain, hassle, time, and heartbreak remain. And are uncompensated.

Re: DocuSign email address database breached and used for phishing campaign

#35

Earlier quoted context omitted.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

Are you sure? I don't know how credit card companies in the US behave, but here in the Netherlands I called up mastercard to ask them whether I am liable for any fraud that occurs if I do something like this (or send credit card info over email, like so many hotels want). The credit card company tells me, yes I am liable for any fraud that occurs, because email and unecrypted text boxes on websites are known to be in…

It seems to be a US law.

https://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cr...

Re: DocuSign email address database breached and used for phishing campaign

#36

Looks like it took them about six days to figure out why their customers were getting spammed. It'd be helpful if they could outline what the "non-core system that allows us to communicate service-related announcements to users via email" actually was. Was this a Mailchimp account that got hacked into or did they have something they managed?

I had the same impression. Pretty sure it was their MailChimp (or similar service) account.

Re: DocuSign email address database breached and used for phishing campaign

#37

Earlier quoted context omitted.

Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

This is not an accurate description of the difference between credit cards and offline debit cards with regard to disputed transactions.

In both cases, fraud disputes are handled in the same way. Either the issuer or the account holder suspects fraudulent transactions and the bank engages an investigation in order to determine veracity of the claim.

Where things differ is that the onus of proof for credit card accounts is on the merchant to prove the transaction is legit. When an offline debit card is used, the funds are deducted from the account when the merchant captures funds and, therefore, the onus of proof lies with the card holder to prove it is fraudulent.

Liability, in this context, is non sequitur as fraud claims exist in either scenario and one party or the other must provide proof to support their position. The other, by definition, is responsible for said funds.

I'm not really sure what you mean regarding "a reversible ledger", as this has nothing to do with credit card transactions.

EDIT: clarified liability phrasing.

Re: DocuSign email address database breached and used for phishing campaign

#39
This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x.

We have already started seeing a tonne of DocuSign phishing emails as others have mentioned. They were already a popular target for phishing users but now with very realistic documents the users are expecting? Nightmare.

[0] https://BreachCanary.com

Re: DocuSign email address database breached and used for phishing campaign

#40

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I strictly started handing out "companyname@mypersonaldomain.tld" as email when interacting with companies. That at least makes routing the inevitable spam to the trash bin slightly easier when a breach occurs. It also provides an indicator of who has (in)voluntarily given away my data.

I do the same with Gmail, just add + at the end (As in username+docusign@gmail.com). Of course this has the drawback of some sites being to restrictive with their checks for valid emails and not allowing the + character
Post reply on HN