Honestly I’m shocked this took so long. For years and years this has smelled like a massive vulnerability to me, just because so constantly I find myself getting docusigns from people I have some kind of business with, without any warning in advance that it’s coming.
At least a couple times a year I find myself calling some banker/travel organizer/administrator in charge of some speaking fee/etc./etc. and asking “hey, I have some Docusign with a weird name on it in my inbox, is that from you?”
(See also, every process within a million miles of the mortgage industry, which seems almost custom-made by fraudsters to help other fraudsters, like the whole practice of mailing out letters saying “Surprise! A servicer change happened, now you need to send a check to this totally other company you’ve never heard of! Trust us, it’s real!”)
The threat was identified 2 years ago. This is a repost.