Kaspersky flags phishing campaign impersonating Zoom and Docusign

TechnologyCybersecurityKaspersky flags phishing campaign impersonating Zoom and Docusign

Attackers are using familiar corporate brands and simple phishing tactics to steal credentials, personal information, and payment details.

Kaspersky has identified an ongoing phishing campaign impersonating Zoom and Docusign, showing that even relatively simple email scams can still pose a serious risk in corporate environments.

The campaign has appeared in multiple waves. In the first, attackers sent fake Docusign communications to corporate accounts across the Middle East, Latin America, Western Europe, Russia, Armenia, and Azerbaijan, with phishing links designed to capture login credentials.

A second wave appeared a little more than a week later using fraudulent Zoom notifications. These emails warned recipients that their accounts were about to be disabled and directed them either to credential-stealing pages or embedded forms asking for personal information and credit-card details.

Zoom Docusign phishing
Kaspersky has detected an ongoing phishing campaign impersonating Zoom and Docusign communications.

Familiar brands make simple phishing effective

The campaign relies on recognizable workplace services rather than highly elaborate technical tricks.

Attackers are banking on the fact that employees routinely receive emails from collaboration and document-signing platforms, making fraudulent messages easier to overlook among legitimate notifications. That familiarity can be especially effective in busy corporate inboxes where users may act quickly without closely checking the sender, destination link, or wording.

“In light of the pace of technological development and the widespread adoption of AI, we often tell people how to distinguish sophisticated fraudulent mailings and schemes,” said Andrey Kovtun, email threats protection group manager at Kaspersky.

“However old primitive methods are still being used and sometimes such simplicity can be effective as employees may overlook any phishing signs amid the massive flood of incoming mail.”

More than 1,000 emails detected

As of September 11, Kaspersky had detected more than 1,000 phishing emails associated with the campaign.

The number underscores how attackers can keep delivering results with established phishing techniques by combining urgency, familiar branding, and common workplace workflows. In this case, the Docusign and Zoom impersonations are designed to prompt fast action before the user pauses to verify the message.

Fake Zoom notifications warn users that their accounts are about to be disabled and direct them to credential-stealing pages or forms.

What businesses can do

Kaspersky recommends combining technical controls with employee awareness rather than depending on users alone to identify suspicious messages.

Suggested measures include dedicated email-security tools, regular cybersecurity training, and extended defense systems that combine endpoint protection with human-risk mitigation. Organizations should also keep employees informed about current phishing tactics and run controlled phishing exercises to identify users or teams that may need additional training.

Organizations should also enable multi-factor authentication on email accounts, particularly for privileged users. Where possible, passwordless options such as authentication tokens or mobile push approvals can add another layer of protection if login credentials are compromised.

The campaign reminds organizations to defend against both emerging AI-assisted attacks and older phishing methods that still exploit routine employee behavior.

More information is available through the Kaspersky website.

Related Posts