Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

71–80 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#71
post #67
post #55

Earlier quoted context omitted.

It is coming from the canary birds in the coal mines or in submarines[0]. They have a higher sensibility to CO than humans. This is now part of the common language to say that you sacrifice an animal or "something" to get early warning of something possibly more dangerous. [0]: https://en.wikipedia.org/wiki/Sentinel_species#Historical_ex...

Just wondering, what exactly is being sacrificed in this specific case?

It is artificial users when their data is used it means your privacy has been breached. In a way a canary is not just a sacrifice but a transparent sacrifice.

Re: DocuSign email address database breached and used for phishing campaign

#72

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

Gorgeous design! Nice to see some cheery bright colors for a change.

Re: DocuSign email address database breached and used for phishing campaign

#73

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused.

Not affiliated, just a happy long-time paying customer.

[1] http://33mail.com/rj37w3

Re: DocuSign email address database breached and used for phishing campaign

#74
post #69

Earlier quoted context omitted.

The postmortem states that the phishing campaign used only a few patterns. "Delete any emails with the subject line, “Completed: [domain name] – Wire transfer for recipient-name Document Ready for Signature” and “Completed [domain name/email address] – Accounting Invoice [Number] Document Ready for Signature”. These emails are not from DocuSign. They were sent by a malicious third party and contain a link to malware…

As a general rule, if you receive an email referencing wire transfers, it's probably bogus.

Given the ratio of spam to ham, as a general rule every email is probably bogus.

Re: DocuSign email address database breached and used for phishing campaign

#75

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

Did you mean "And relax" in your how it works steps?

Re: DocuSign email address database breached and used for phishing campaign

#76

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

Did you mean "And relax" in your how it works steps?

I do! Well spotted, I'll fix that one shortly

Edit: fixed :)

Re: DocuSign email address database breached and used for phishing campaign

#77
post #73

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused. Not affiliated, just a happy long-time paying customer. [1] http://33mail.com/rj37w3

I don't know what the HN policy on referral links is, but here's a link without affiliate tracking:

http://33mail.com

Re: DocuSign email address database breached and used for phishing campaign

#78

I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…

> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction.

When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you.

I've been doing this for years, each different company gets a unique email address. Real easy to see who has lost track of their email database, and very easy to turn off those that turn spammy as their business declines and they get ever more desperate to generate sales from their existing "customer list"

Re: DocuSign email address database breached and used for phishing campaign

#79

Earlier quoted context omitted.

AliExpress does this, they don't accept "aliexpress@foo.bar". I suppose it's meant to stop you from providing "foo@aliexpress.com", implemented lazily by rejecting anything that contains the substring "aliexpress". Best response I've received when giving an email address of the form "company@mydoma.in" to a representative in person was "oh you work here too?". The concept of catch-all domains is so foreign to most la…

A catchall on my domain was all fun and games till the second dictionary spam run.

I haven't had any issues with that and I've been using a catch all setup for about 7-10 years. Most spam arrives on the actual primary email address.

Re: DocuSign email address database breached and used for phishing campaign

#80
post #73

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused. Not affiliated, just a happy long-time paying customer. [1] http://33mail.com/rj37w3

I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically
Post reply on HN