Stay Sharp with Document Signing Requests
Posted in: News
Digital document signing platforms like Docusign, Adobe Sign, and Dropbox Sign make it easy to approve campus forms, contracts, and agreements securely. Unfortunately, cybercriminals have learned to mimic these legitimate services to trick users into revealing personal information, university credentials, or payment data.
The Threat: Phishing Through 鈥淪ign This Document鈥 Emails
Phishing attackers often send fake document signing requests that look strikingly real 鈥 complete with university logos, familiar sender names, or 鈥渦rgent鈥 subjects like:
- Action Required: Your Document is Ready for Signature
- Your Initial Deposit was processed. Review Below
- Faculty Contract Update
These messages may contain links to convincing look-alike websites where you鈥檙e prompted to 鈥渟ign in鈥 with your university or personal email credentials. Once entered, your login details go straight to the attacker.
Spot the Signs of a Fake
Before clicking 鈥淩eview Document鈥, pause and check:
- Sender鈥檚 Address: Is it from a legitimate service domain (i.e. @docusign.com, @adobesign.com) 鈥 not a random or misspelled email address? Does the sender information match the person鈥檚 identity?
- Unexpected Request: Were you actually expecting a document from this person or department?
- Link Preview: Hover over the button or link 鈥 does it lead to the official site or an unfamiliar web address?
- Generic Language: Real university requests often include specific details (department name, contact information, context). Phishing messages tend to be vague.
What to Do if You Receive One
- Don鈥檛 click the link.
- Report it immediately using the Phish Alert Button (PAB).
- Verify directly with the sender through a separate, known communication channel.
If You Already Clicked or Entered Credentials
- Change your password right away 鈥 especially if it鈥檚 your Montclair login.
- Report the incident to the IT Service Desk or by using the PAB.
- Enable Multi-Factor Authentication (MFA) on all of your accounts; Duo can be used for your personal accounts too!
Stay Informed
Cybercriminals constantly adapt their tactics. Staying skeptical of unexpected document requests 鈥 even when they look official 鈥 is one of the simplest and most effective ways to protect yourself and the campus network.
Remember: When in double, report before you sign.聽
“Before you click 鈥楽ign,鈥 make sure you鈥檙e not autographing a phishing scam. We鈥檇 hate for your biggest signature of the year to go to a hacker.”
鈥 Emily Harris
Chief Information Security Officer
Want to Learn More?
BitDefender |
WeLiveSecurity |
Infosecurity Magazine |
Kaspersky |