03/06/2026
Welcome to another episode of Tales from the Hacked....real stories about attacks on our clients that we prevented or stopped in their tracks. "A Docusign Account Goes Phishing..." Chuck is a client of ours. He saw a new email - a Docusign stating it was from his colleague Gilbert. Yes, it was a real Docusign account that sent it. What he did not know: attackers opened this Docusign account in Gilbert's name with a domain name that was one letter off the real one Gilbert's company uses (the real domain name ends in "attorneys.com" - the one bought by the attacker ends in "attoneys.com"). This means the attackers spent money to execute this attack. They bought a domain name, email infrastructure, and third party applications (Docusign). This was an attack targeting a small business. You are never too small to be a target. The real kicker? The Docusign form sent Chuck to a man in the middle attack fake form that captured his Microsoft 365 password and 2 factor code, giving the attacker access to Chuck's mailbox. Microsoft published their logs 4 minutes after the login by the attacker, a proactive monitoring IT threat detection and response tool included in our P3C proactive plans locked Chuck's account within 56 seconds of the log being published. The attacker had access to the account for less than 5 minutes - and the attacker did not have time to do anything. This is why it is important to have an IT provider watching your back. Contact us for an audit of your Microsoft 365 environment - even if you have internal or existing IT help - we will run the assessment for you.