Kaspersky has uncovered an ongoing phishing campaign impersonating official Zoom and DocuSign communications, with more than a thousand such emails detected as of 11 September. The campaign, aimed at corporate accounts, ran in two distinct waves and remains active.
The first wave involved emails impersonating official DocuSign communications sent to corporate accounts across the Middle East, Latin America, Western Europe, Russia, Armenia and Azerbaijan, each carrying phishing links designed to steal credentials. A second wave, which began just over a week later, poses as Zoom notifications warning users that their accounts are about to be disabled. This wave combines phishing links that redirect victims to credential-stealing pages with embedded forms soliciting personal information and credit card details.
Simple tactics still work
What stands out about the campaign is how little sophistication it needs to succeed. Kaspersky notes that even as more advanced, AI-generated phishing attempts draw attention from security teams, basic impersonation of widely used corporate tools can still slip past employees overwhelmed by the volume of daily email.
“In light of the pace of technological development and the widespread adoption of AI, we often tell people how to distinguish sophisticated fraudulent mailings and schemes. However old primitive methods are still being used and sometimes such simplicity can be effective as employees may overlook any phishing signs amid the massive flood of incoming mail,” said Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky. “Even these low-tech tactics should be caught by dedicated security solutions, so a company’s cyber safety doesn’t depend solely on the human factor.”
What Kaspersky recommends
Kaspersky is urging organisations to deploy dedicated email security solutions capable of catching both traditional and AI-generated phishing, run regular security awareness training, and combine endpoint threat protection with human-risk mitigation tools. It also recommends conducting controlled phishing tests to identify high-risk employee groups and deploying multi-factor authentication across all email accounts, particularly for privileged users, using passwordless options such as tokens or mobile push where possible.



Share your thoughts