(June 20, 2025) – The American Hospital Association advises that it has received credible field reports regarding an ongoing phishing email campaign utilizing the legitimate DocuSign email infrastructure. Reports indicate that these phishing emails have been sent to various health care entities. The email appears to originate from a state-level Department of Public Health and requests a signature on a document. Please check the sending address in the email, as it does not end with the usual "gov" domain.
Visit the Cybersecurity Advisory on Phishing Emails Targeting Health Care | AHA for more information, and share it with your IT security team and your organization. The FBI has requested that if anyone in your organization receives a DocuSign email with the described phishing scheme, please forward the email as an attachment from your organization or send the message directly to the FBI at mp_cyberintake@fbi.gov.
--Larry Van Der Wege