UIndy IT Tech Guides

Phishing scam using Docusign

Updated on

Fraudsters have continued their phishing efforts recently targeting UIndy accounts with bogus emails using Docusign for PayPal transaction notifications. These are NOT real. They are just trying to get your personally identifiable information (PII).

How to identify scam

Here are some specific red flags to recognize in this phishing email:

  1. Financial transactions to/from someone or some place that you don't recognize 
  2. Sense of urgency
  3. Email address using multiple periods in their email address name - This is a practice to obfuscate an email address and/or bypass any spam filters that might have caught their true email address 
  4. Paypal has its own transaction notification system and would not use Docusign
  5. In the body of the email, there is no mention about signing a document (which is typically what Docusign is used for)
Depicts Docusign phishing scam email

What to do if you suspect a scam or have been scammed

  • If you are unsure or believe something is fraudulent, Report a security issue and copy/paste the email or attached a printed copy for us to review. 
  • If you have already sent money, contact your bank or credit card company right away to close the account or dispute the charges.  Then, contact UIPD ([email protected]).
Previous Article You’ve fallen for a phishing attack
Next Article Faculty conduct reference scam
UIndy Works: portal for campus service and support UIndy Works