Forget AI: This Basic Zoom Phishing Scam Is Hitting Inboxes

0Shares

While the world worries about AI-powered fraud, a simpler Zoom phishing scam is landing in work inboxes. Cybersecurity firm Kaspersky says a phishing campaign is posing as Zoom and Docusign to steal logins and card details. It’s basic, but it can still work.

Kaspersky’s team uncovered the campaign, calling it a case of spammers relying on tried-and-tested phishing schemes. The hope, according to the company, is that at least some of the emails will succeed.

A phishing campaign impersonating Zoom and Docusign targeted corporate email users with messages designed to steal sensitive information.
A phishing campaign impersonating Zoom and Docusign targeted corporate email users with messages designed to steal sensitive information.

How the Fake Zoom and Docusign Phishing Emails Work

The campaign arrived in two waves. First came emails posing as official Docusign messages, aimed at corporate accounts across the Middle East, Latin America, Western Europe, Russia, Armenia and Azerbaijan.

Each Docusign email carried phishing links built to steal credentials. A little more than a week later, a second wave hit, this time posing as official Zoom notifications.

Those Zoom emails warned users their accounts were about to be disabled. It’s a classic pressure tactic meant to rush people into clicking before they think. Kaspersky’s findings describe impersonation of both brands, not a breach of their systems.

Kaspersky says the attackers used two simple lures. One used phishing links that redirected recipients to credential-stealing pages. The other used embedded forms that asked for personal information and credit card details.

Why Simple Phishing Scams Still Fool Employees

As of Sept. 11, Kaspersky had detected more than 1,000 phishing emails tied to the campaign. That total covers both the Docusign and Zoom waves. The Zoom wave was still active when the company published its findings.

Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky, said old, primitive methods are still in use. He added that simplicity can pay off because employees may overlook warning signs amid a flood of incoming mail.

Kovtun also said fraudsters choose brands widely used in corporate settings to mimic real mailings. Even low-tech tactics should be caught by dedicated security tools, he said. A company’s cyber safety should not rest on staff alone.

Related Post:  From EVs to Androids: XPENG's IRON Robot Marks a New Era

Kaspersky recommends a dedicated email security tool, such as its own Kaspersky Security for Mail Server. The company says it addresses both traditional and modern phishing, using advanced heuristics that can spot AI-generated attempts.

Kaspersky also urges regular staff training and controlled phishing tests to find high-risk groups. Employees should be reminded that fake messages can look like official emails.

The company also advises multi-factor authentication, or MFA, on all email accounts, especially for privileged users. Where possible, it suggests passwordless options such as tokens or mobile push.

Simple checks still help. Look at the sender’s address and hover over links before clicking, especially when a message threatens to close an account.

0Shares

Leave a Reply