Two Trusted Brands, One Devastating Scam

In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their signature — tied to a PayPal invoice. One click led to a credential harvesting page that looked indistinguishable from a real PayPal login.

I've tracked phishing trends for over a decade, and this PayPal DocuSign phishing tactic is one of the most effective social engineering plays I've seen. It exploits the implicit trust people place in both brands. DocuSign emails get opened because people expect them in business contexts. PayPal creates urgency because money is involved. Combined, they create a near-perfect lure.

According to the FBI IC3 2023 Annual Report, phishing remained the most reported cybercrime category with over 298,000 complaints. Attacks like the PayPal DocuSign phishing campaign are a big reason why.

How the PayPal DocuSign Phishing Attack Actually Works

Step 1: The DocuSign Lure Email

The attack starts with an email that mimics DocuSign's notification format almost perfectly. The subject line usually reads something like "Complete your document: PayPal Invoice #8847291" or "Action Required: Review and Sign Payment Agreement." The sender address may use a lookalike domain — something like docusign-notify.com instead of docusign.com.

In many cases, threat actors use legitimate DocuSign accounts they've compromised or trial accounts to send the initial email. This means the email actually passes SPF, DKIM, and DMARC authentication checks, sailing right through most email filters.

Step 2: The Fake Payment Document

Clicking "Review Document" takes the target to a page that looks like a DocuSign signing interface. The document displayed is a PayPal invoice — often for a few hundred dollars — with a "Pay Now" or "Dispute This Charge" button embedded inside.

This is the social engineering hook. If you didn't authorize a payment, your instinct is to click "Dispute" immediately. That urgency overrides caution.

Step 3: Credential Harvesting

The "Dispute" or "Pay" button redirects to a phishing page that replicates PayPal's login screen. The victim enters their email and password, which go straight to the attacker's server. Some variants also prompt for credit card information or multi-factor authentication codes in real time, using adversary-in-the-middle (AitM) proxy tools.

Step 4: Account Takeover and Monetization

With stolen credentials, attackers drain PayPal balances, make unauthorized purchases, or pivot to other accounts where the victim reused the same password. In business contexts, this can escalate to business email compromise, where the attacker uses the compromised account to send fraudulent invoices to partners and customers.

Why Email Filters Miss This Attack

This is the part that frustrates security teams the most. Traditional email security relies heavily on domain reputation and authentication protocols. When threat actors use legitimate DocuSign infrastructure to send phishing emails, those emails look authentic because they are authentic at the transport layer.

The malicious payload isn't an attachment — it's a link to an external page. Many secure email gateways won't flag a DocuSign link as suspicious. The phishing page itself is typically hosted on a compromised legitimate website or a freshly spun-up domain that hasn't been blacklisted yet.

This is exactly why organizations need layered defenses. Technology alone won't catch everything. Your employees are the last line of defense, and they need cybersecurity awareness training that covers exactly these kinds of multi-brand impersonation attacks.

What Does a PayPal DocuSign Phishing Email Look Like?

Here are the red flags I tell every security team to watch for:

  • Unexpected DocuSign email: You didn't request a document or expect an invoice. That alone should trigger suspicion.
  • Financial urgency: Any email combining "payment," "invoice," and "action required" deserves extra scrutiny.
  • Mismatched sender domain: Hover over the sender address. Legitimate DocuSign emails come from @docusign.net or @docusign.com — not variations.
  • Generic greeting: "Dear Customer" instead of your actual name.
  • Suspicious link destinations: Hover over buttons before clicking. If the URL doesn't go to paypal.com or docusign.net, stop.
  • Pressure to act immediately: Phrases like "your account will be suspended" or "unauthorized charge detected" are classic social engineering pressure tactics.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's Cost of a Data Breach Report 2024 found the global average cost of a data breach hit $4.88 million. Phishing was the second most common initial attack vector, and credential theft driven by phishing had one of the longest average times to identify and contain — 292 days.

PayPal DocuSign phishing attacks are particularly costly because they target financial credentials directly. A single compromised PayPal business account can lead to fraudulent wire transfers, stolen customer data, and regulatory headaches that last months.

The Verizon 2024 Data Breach Investigations Report confirmed that the human element was involved in 68% of breaches. Phishing and pretexting remain the top social engineering tactics. Your team's ability to spot these attacks matters more than any single technology investment.

How to Protect Your Organization Right Now

Train Your People on Multi-Brand Phishing Tactics

Generic "don't click suspicious links" advice doesn't cut it anymore. Your employees need to see realistic examples of attacks like the PayPal DocuSign phishing campaign. Run targeted phishing awareness training for organizations that uses simulations based on real-world attack patterns — not outdated templates from five years ago.

Enforce Multi-Factor Authentication Everywhere

Even if credentials get stolen, multi-factor authentication (MFA) can stop account takeover. Use phishing-resistant MFA like FIDO2 hardware keys or passkeys — not just SMS codes, which AitM attacks can intercept in real time.

Implement a Zero Trust Email Verification Policy

Any email requesting payment, signature, or credential entry should be verified out-of-band. Teach employees to go directly to PayPal or DocuSign by typing the URL into their browser — never by clicking email links. This single habit neutralizes most phishing attacks.

Deploy URL Rewriting and Time-of-Click Analysis

Modern email security platforms can rewrite URLs and check them at the moment the user clicks, not just at delivery time. This catches phishing pages that go live after the email is delivered — a common evasion tactic.

Monitor for Compromised Credentials

Use dark web monitoring services to detect if employee credentials appear in breach databases. CISA regularly publishes guidance on credential hygiene and incident response that every security team should reference.

If you or an employee already clicked, here's the immediate response playbook:

  • Change your PayPal password immediately from a known-clean device.
  • Enable MFA on PayPal and any account that shares the same password.
  • Check PayPal transaction history for unauthorized activity and report it through PayPal's Resolution Center.
  • Report the phishing email to PayPal at [email protected] and to DocuSign at [email protected].
  • File a report with the FBI's Internet Crime Complaint Center (IC3).
  • Alert your IT/security team so they can check for broader compromise and block the phishing domain across the organization.

This Attack Isn't Going Away

PayPal DocuSign phishing attacks work because they exploit brand trust, financial urgency, and the limitations of automated email security — all at once. Threat actors will keep refining this playbook because it delivers results.

Your best defense is a workforce that recognizes these attacks before they click. That starts with realistic, ongoing training — not a once-a-year compliance checkbox. Build a security culture where verifying before clicking is second nature, and attacks like these lose their power.