Kaspersky Discovered Phishing Campaign Impersonating Zoom
The campaign targeted corporate accounts across multiple regions using credential-stealing links and fake forms.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you feel confident in your ability to identify a sophisticated phishing email?
Kaspersky uncovered a widespread phishing campaign in September 2026 that impersonated Zoom and Docusign. The attacks targeted corporate accounts across the Middle East, Latin America, Western Europe, Russia, Armenia, and Azerbaijan.
Why it matters
Fraudsters continue to leverage basic, tried-and-tested phishing schemes to exploit busy corporate employees and steal sensitive credentials. By mimicking common business tools, the attackers hope to gain unauthorized access to organizational networks.
The campaign involved more than 1,000 malicious emails as of September 2026. Attackers utilized phishing links for credential theft and embedded forms designed to capture personal information and credit-card data.
The players
Kaspersky
Kaspersky is a global cybersecurity and anti-virus provider that monitors and researches digital threats.
Zoom
Zoom is a major communications technology platform that provides video telephony and online chat services.
Docusign
Docusign is a widely used software company that allows organizations to manage electronic agreements and digital signatures.
The details
The attackers sent emails mimicking official communications to trick recipients into clicking links or filling out embedded forms. These methods allowed the actors to harvest sensitive data from employees working within targeted international corporate accounts.
Timeline
More than 1,000 phishing emails were detected in September 2026.
The Tech Race
This campaign follows a long-documented trend of attackers impersonating essential business software to bypass standard corporate security filters. It reflects the ongoing battle between cybersecurity firms and actors utilizing basic social engineering to exploit software ecosystems.
Corporate users should exercise caution when receiving unexpected communications from platforms like Zoom or Docusign. Avoid entering credentials or credit card details into embedded forms within emails to prevent data theft.
The takeaway
Employees should always verify the sender's address and avoid clicking links in unsolicited emails to maintain network security. Relying on official company portals rather than email links is an effective way to mitigate these common social engineering risks.
Further reading
For more information on current digital threats, visit the Cybersecurity section.
Live Poll
Do you feel confident in your ability to identify a sophisticated phishing email?







