Kaspersky Uncovered Phishing Campaign Impersonating Zoom
The campaign targeted corporate accounts across multiple regions using credential-stealing links and forms.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you feel confident in your ability to identify a sophisticated phishing email?
As of September 2026, researchers identified over 1,000 phishing emails masquerading as official communication from Zoom and Docusign. This campaign leveraged malicious links and embedded forms to compromise corporate credentials and capture financial data.
Why it matters
The campaign demonstrates the persistent effectiveness of basic social engineering schemes that exploit the high volume of daily digital communication. By impersonating ubiquitous workplace tools, attackers continue to bypass human vigilance in corporate environments.
The campaign utilized over 1,000 detected phishing emails to target organizations across the Middle East, Latin America, Western Europe, Russia, Armenia, and Azerbaijan. Researchers confirmed that the primary attack vectors included credential-stealing links and embedded forms.
The players
Kaspersky
A global cybersecurity firm known for its threat intelligence research and anti-malware software solutions.
Zoom
A communications company providing a widely used enterprise platform for video conferencing and digital collaboration.
Docusign
A cloud-based platform specializing in electronic signature technology and digital document management.
The details
Attackers initiated the campaign by sending emails that impersonated official correspondence from common business software platforms. In the first phase, targets were redirected to external pages designed to harvest login credentials. A subsequent wave of the campaign shifted to using embedded forms within the emails to directly solicit personal information and credit-card details from corporate users.
Timeline
September 2026: More than 1,000 phishing emails were detected by security researchers.
The Tech Race
This activity follows a long-standing pattern of attackers leveraging trusted brand identities to facilitate business email compromise as documented in the FBI Internet Crime Complaint Center's annual reports. The persistence of these schemes highlights the ongoing challenges in corporate endpoint security despite advances in threat detection.
Corporate users should exercise caution with unsolicited email communications, even those appearing to originate from familiar enterprise software providers. IT departments are advised to monitor for suspicious sign-in patterns and enforce multi-factor authentication as the primary defense against credential harvesting.
The takeaway
Organizations should view this campaign as a reminder that attackers continue to favor low-complexity phishing over sophisticated exploits. Security leaders should track threat intelligence updates from vendors like Kaspersky to stay informed on evolving impersonation tactics targeting their specific industries.
Further reading
For broader analysis on how organizations defend against social engineering, visit Cybersecurity.
Live Poll
Do you feel confident in your ability to identify a sophisticated phishing email?






