A documented phishing campaign used legitimate DocuSign accounts, templates, and API-based sending features to deliver fake PayPal-themed invoices and fraud alerts. The message may look like a DocuSign notification, but that does not make its PayPal claim—or its phone number—legitimate.
Do not call the number, click the email’s links, reply, or open unexpected attachments. Instead, sign in to PayPal through its app or by typing paypal.com yourself and check your activity there.
The short version
- A genuine DocuSign delivery can contain fraudulent content.
- The reported campaign used DocuSign’s legitimate sending infrastructure; available evidence does not establish that DocuSign was hacked.
- The likely scam goal was to get recipients to call a fake “fraud prevention” number, where an operator could request money, passwords, one-time codes, card details, or remote access.
- The exact campaign’s current activity is unknown. Malwarebytes documented the operation on March 4, 2025; that report does not establish its volume or whether the same templates remain active in 2026.
What the reported email looked like
According to Malwarebytes’ March 4, 2025 report, the messages used PayPal branding or PayPal-themed invoice language and claimed that the recipient’s account had made an unauthorized Coinbase transaction. One sample cited a charge of $755.38, included a transaction identifier, and instructed the recipient to contact a supposed fraud-prevention team.
The message appeared as a DocuSign document even though the alleged transaction did not require a signature. Reported warning signs also included a Gmail contact address, mismatched or nonexistent recipient details, and a phone number supplied by the scammer. Do not publish or call that number; it is reported scam infrastructure, not a PayPal support channel.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How the DocuSign abuse worked
- The scammers created or obtained DocuSign accounts.
- They used legitimate DocuSign templates and API-enabled sending functions.
- They wrapped a fake PayPal invoice or transaction alert in a delivery format recipients recognized.
- The urgent transaction claim pushed the recipient toward a phone conversation.
- An operator could then attempt payment fraud, account takeover, or remote-access fraud.
An API is an interface that lets authorized customers automate tasks such as sending documents. “Abuses the DocuSign API” describes misuse of that capability; it is not, based on the available report, evidence of a software vulnerability or unauthorized access to DocuSign’s systems. The trusted delivery platform may improve credibility or help a message evade some email-security controls, but it does not authenticate the document’s claims.
The red flags that matter most
- You were not expecting the document. An unsolicited invoice or envelope deserves independent verification.
- The message creates urgency. Immediate calls, refund deadlines, or threats of additional loss are classic pressure tactics.
- It tells you to call first. Legitimate support should be contacted through a number obtained independently, not one supplied by a suspicious email.
- The service and action do not fit. DocuSign is a document-delivery and signing service. Its appearance does not prove that PayPal sent a transaction alert.
- Addresses do not align. Check the visible sender, actual sending address, reply address, contact address, and recipient address. A Gmail address or mismatch is suspicious, although address checking alone is not conclusive.
- The alleged transaction is missing from PayPal. A charge that does not appear when you sign in independently is a strong reason to treat the message as fraudulent.
- The caller requests secrets or control. Passwords, MFA codes, gift cards, cryptocurrency, bank transfers, card details, and unrestricted remote access are major warning signs.
How to verify it safely
- Do not click buttons, open attachments, call the listed number, or reply.
- Open the PayPal app or a new browser window and manually enter paypal.com.
- Review recent activity, notifications, invoices, and disputes. Do not use a link in the suspicious email.
- If the transaction is absent from PayPal, treat the message as a scam. Do not call merely “to check.”
- If you want to determine whether a DocuSign envelope exists, navigate to DocuSign independently rather than using the email’s button.
- Use DocuSign’s independent document-access workflow, including its security-code process if presented by the official site. An error may mean the envelope was removed or never existed.
Even a valid envelope does not prove that PayPal authorized its contents. These are separate questions: Was an envelope created? Who created or sent it? Is the alleged PayPal transaction real? Only the last question is answered by checking your PayPal account.
What to do if you only received the email
Preserve the original message if you may need its headers, envelope ID, security code, timestamp, or screenshots. Do not forward it to coworkers without a warning, because forwarding can spread active links or phone numbers.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For suspicious messages, PayPal’s U.S. guidance says to forward the entire email to [email protected], then delete it. Use PayPal’s official suspicious-message instructions if you are outside the U.S. or need updated directions.
Report the abusive envelope or account through DocuSign’s current abuse-reporting process. Menu names and URLs can change, so reach DocuSign independently rather than using a link in the message. Include the original evidence.
If you called the number
- Hang up and stop communicating with the caller.
- Do not install remote-management software or share passwords, card details, bank information, or MFA codes.
- If you granted remote access, disconnect the device from the internet and obtain trusted technical help.
- From a clean device, change PayPal, email, and financial-account passwords. Change reused passwords elsewhere too.
- Revoke active sessions, inspect recovery information, forwarding rules, connected apps, and payment methods.
- Contact your bank or card issuer using the number on the card or an official statement.
- Expect follow-up “security,” “refund,” or “recovery” calls. They may be part of the same fraud.
If you clicked
If you clicked but entered nothing, close the page and do not download or run files. Check the browser’s download folder, remove unexpected files, and update the operating system, browser, and security software. Run a security scan if anything downloaded or executed. Continue monitoring your accounts because a click can lead to follow-up targeting even when no password was entered.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Windows 11 includes Microsoft Defender Antivirus at no extra charge, according to Microsoft. Security software can help with malicious downloads and websites, but it cannot reverse a payment or reliably stop a person from voluntarily giving information to a phone scammer.
If you shared credentials, an MFA code, or money
- Change the exposed password immediately from a clean device, and replace it anywhere reused.
- Enable passkeys or phishing-resistant MFA where available.
- Review logins, recovery email addresses, phone numbers, forwarding rules, connected applications, and payment methods.
- Contact PayPal and your email provider through their official sites or apps.
- Call your bank or card issuer immediately using a trusted number. Ask whether an account, card, or transfer must be blocked or replaced and ask about fraud-recovery deadlines.
- Use PayPal’s official dispute page for an actual unauthorized PayPal transaction.
An MFA code is not safe to share with a caller. A scammer may already know the supposed transaction details and be trying to use a legitimate code to take over the account.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat businesses and help desks should do
Train staff that trusted SaaS delivery does not equal trusted content. Flag unexpected DocuSign envelopes containing payment, refund, or account-security language, especially when they include phone-first instructions.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Preserve full headers and envelope metadata, and establish one playbook covering payment fraud, account takeover, and remote-access incidents. DMARC, SPF, DKIM, inbound URL analysis, and brand-impersonation detection remain useful, but none should be expected to block every message delivered through a legitimate platform.
Report suspected impersonation to PayPal and abusive envelopes to DocuSign. Extracted phone numbers and domains can be added to internal warnings, but avoid circulating them without context.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Optional device protection
Someone who only received the email may not need to buy security software. Built-in Windows protection is a reasonable baseline, and official PayPal and bank reporting channels are more important than any paid product.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Malwarebytes describes its consumer products and Scam Guard features at Malwarebytes for Home and Scam Guard. An additional layer may be useful after a malicious link or download, or for broader browser and scam detection across devices. It cannot verify a PayPal transaction, recover a voluntary payment, or guarantee protection from phone-based social engineering.
Frequently Asked Questions
Does PayPal normally use DocuSign for fraud alerts?
Do not assume that a DocuSign-branded envelope is a normal PayPal workflow. Verify any alleged transaction inside PayPal’s independently opened app or website.
Should I call PayPal about the email?
Only use contact details obtained from PayPal’s official website, app, card, or statement—not the phone number in the email.
What if there is no transaction in my PayPal account?
Treat the message as fraudulent, report it to PayPal and DocuSign, preserve the evidence, and delete it. If you shared information, follow the account-security steps above.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




