Kaspersky Uncovered Phishing Campaign Impersonating Zoom

The campaign targeted corporate accounts across multiple regions using credential-stealing links and forms.

Updated on Sept. 28, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a sharp-edged fiber-optic node, symbolizing cybersecurity threats in corporate digital systems.
Researchers uncovered a widespread phishing campaign as of September 2026, where attackers impersonated Zoom and Docusign to harvest corporate credentials. AI Illustration. Upload story photo >

Live Poll

Do you feel confident in your ability to identify a sophisticated phishing email?

As of September 2026, researchers identified over 1,000 phishing emails masquerading as official communication from Zoom and Docusign. This campaign leveraged malicious links and embedded forms to compromise corporate credentials and capture financial data.

Why it matters

The campaign demonstrates the persistent effectiveness of basic social engineering schemes that exploit the high volume of daily digital communication. By impersonating ubiquitous workplace tools, attackers continue to bypass human vigilance in corporate environments.

The campaign utilized over 1,000 detected phishing emails to target organizations across the Middle East, Latin America, Western Europe, Russia, Armenia, and Azerbaijan. Researchers confirmed that the primary attack vectors included credential-stealing links and embedded forms.

The players

Kaspersky

A global cybersecurity firm known for its threat intelligence research and anti-malware software solutions.

Zoom

A communications company providing a widely used enterprise platform for video conferencing and digital collaboration.

Docusign

A cloud-based platform specializing in electronic signature technology and digital document management.

The details

Attackers initiated the campaign by sending emails that impersonated official correspondence from common business software platforms. In the first phase, targets were redirected to external pages designed to harvest login credentials. A subsequent wave of the campaign shifted to using embedded forms within the emails to directly solicit personal information and credit-card details from corporate users.

Timeline

  1. September 2026: More than 1,000 phishing emails were detected by security researchers.

The Tech Race

This activity follows a long-standing pattern of attackers leveraging trusted brand identities to facilitate business email compromise as documented in the FBI Internet Crime Complaint Center's annual reports. The persistence of these schemes highlights the ongoing challenges in corporate endpoint security despite advances in threat detection.

Corporate users should exercise caution with unsolicited email communications, even those appearing to originate from familiar enterprise software providers. IT departments are advised to monitor for suspicious sign-in patterns and enforce multi-factor authentication as the primary defense against credential harvesting.

The takeaway

Organizations should view this campaign as a reminder that attackers continue to favor low-complexity phishing over sophisticated exploits. Security leaders should track threat intelligence updates from vendors like Kaspersky to stay informed on evolving impersonation tactics targeting their specific industries.

Further reading

For broader analysis on how organizations defend against social engineering, visit Cybersecurity.

Live Poll

Do you feel confident in your ability to identify a sophisticated phishing email?

Kaspersky Uncovered Phishing Campaign Impersonating Zoom