How it works
This attack wears the costume of a real deal. You get an email that looks like a DocuSign envelope or a "contract ready for signature" notice, sometimes after a friendly first message about a paid collaboration. The "Review document" button opens a page that imitates DocuSign or a generic e-signature portal. To view the contract, it asks you to authenticate, and the fastest option offered is "Sign in with Google." That step hands your credentials to the attacker. Because the lure is a contract you might genuinely be expecting, the pull to just sign in and read it is strong. Some versions skip the portal and attach an HTML file that opens its own login form when you double-click it.
Real DocuSign envelopes come from docusign.net domains and never require your Google password to open a document. Real sponsors send a signable link that opens the document directly or asks for a one-time code sent to your email, not your full account login.
The tell-tale signals
- The sender is a free webmail address or an unrelated domain claiming to be the brand or a signing service.
- The domain is young and missing SPF or DMARC.
- A "sign in with Google" wall stands between you and a document that should just open.
- The link text and the real destination are different domains.
- If there is an attachment, it is an archive rather than a plain PDF.
What to do
Treat any "sign in with Google to view this contract" screen as a phishing page and stop there. A document does not need your email password to be read. If the deal is real, ask the sender to send the contract as a direct PDF or through a verifiable DocuSign envelope, and confirm the company through its official site before signing anything. Do not enter your Google login on the portal, and do not open an archive or HTML attachment sent in place of a document. If you already signed in, change your password from a trusted device, sign out of all sessions, and review third-party access on your Google permissions page. LegitSponsor can weigh the sender and link evidence on the original email so you are not judging it by the DocuSign logo alone.