You receive an email that looks like it’s from DocuSign (or another e‑signature service) saying “Your documents are ready to sign.” The button or link takes you to a website that looks like a Microsoft, Google, or company login page. If you enter your email and password there, the scammers steal your login and can get into your email and other accounts.
Step 1: An email claims a contract, invoice, or certificate is waiting for your signature.
Step 2: The email includes a button like “Review Document” or “View Documents.”
Step 3: The link leads to a fake login page (often Microsoft 365/Outlook or Google) on an unrelated website.
Step 4: If you sign in, the scammers capture your password and may immediately try it on your email and other accounts.
Step 5: Once in your inbox, they can reset passwords, read messages, and send new scams to your contacts.
✓ Do this
✗ Avoid this
Do not reply, pay, or use contact details in an unexpected message. Verify through the official app or website, then report what you saw so the Archive can connect related patterns.
Don’t call numbers or click links in unexpected messages. Go directly to the company’s official site or app and contact support from there.