In the first week of November 2024, security firm Wallarm publish an article about an intriguing scam involving DocuSign, a popular electronic signature solution provider.
Attackers are leveraging DocuSign's technology to send fake invoices that look remarkably authentic. But what makes these attacks particularly vicious is the level of sophistication they require.
Simply put, DocuSign's API, designed to streamline electronic agreements, has been weaponised by scammers to deceive unsuspecting victims. Scammers are using legitimate paid accounts to create and send Invoices that appear to be authentic. The attack involves:
Attackers are not only mimicking legitimate companies but are actively integrating themselves into genuine communication networks to carry out their malicious Invoice fraud.
Invoice fraud, once a niche concern, has evolved into a widespread challenge for organisations of all scales. The practice involves submitting false or altered invoices to obtain funds illegally and effectively disguising theft as legitimate business activity.
The most common type of Invoice fraud are:
But this list is far from exhaustive; thanks to the integration of digital tools and platforms, anyone can create invoices in seconds. The rest is a matter of creativity. However, while technology has amplified the reach of fraud, human error is often the unintentional catalyst. Large businesses process thousands of invoices daily, and fraudsters rely on the likelihood that not all invoices will be subjected to rigorous examination. In some “not so” rare cases, internal employees can provide sensitive information or deliberately approve fraudulent invoices.
But these practices are avoidable. By listening to the challenges and needs of Finance professionals, Betaramps is building a simple, secure, and automated way for businesses to trade safely. With blockchain technology and AI, fraud from fake invoices is virtually nonexistent.
Learn more at Betaramps.com
Sources
https://informationsecuritybuzz.com/attackers-exploit-docusign-api/
https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/