Digital signature service DocuSign detected emails purporting to come from the company were sent by an unauthorised third-party. The hackers then sent out phishing emails to those email addresses. The emails had subject lines like: “Completed: [domain name] Wire Transfer Instructions for [recipient name] Document Ready for Signature or Document Ready for signature The company is asking users to forward them to [email protected], before deleting them from their inbox.”]

