Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Phishing

Fake Zoom and Docusign emails target corporate inboxes

Kaspersky found more than 1,000 phishing emails posing as Docusign and Zoom to steal logins, personal details and card numbers.

By · Published · Updated · 4 min read

Fake Zoom and Docusign emails target corporate inboxes

Kaspersky has found an ongoing phishing campaign impersonating Docusign and Zoom, the company says.

Two waves

  1. Docusign: emails sent to corporate accounts in the Middle East, Latin America, Western Europe, Russia, Armenia and Azerbaijan, with links to credential-stealing pages.
  2. Zoom: a week later, emails warning that users' accounts were about to be disabled. These used fake login pages and embedded forms asking for personal and credit card details.

More than 1,000 phishing emails had been detected by September 2026.

Why simple scams still work

Kaspersky notes that even basic phishing succeeds because staff are flooded with email, and attackers pick brands that every office uses daily. A "document waiting for signature" or "account suspended" notice looks routine.

How to spot them

  • Hover over links: real Docusign links go to docusign.net or docusign.com, real Zoom links to zoom.us.
  • Zoom will not ask for your card details to keep a free account active.
  • If unsure, open the app or website directly instead of clicking.

Sources

Read next