Fake e-signature emails arrive as a document waiting for your signature — a contract, an HR form, a supplier agreement — and link to a page that collects your email password before showing anything to sign. This 2026 guide trains staff to treat every sign-here email as unverified until checked, and to report the fakes within minutes.
TL;DR
- Fake e-signature emails steal logins through cloned signing pages.
- The tells are unexpected documents, lookalike domains and login walls before the document.
- The response is stop, open the signing platform through the official site, then report.
- Cyber Aware phishing simulations rehearse the check before the real email arrives.
Why this matters
E-signature services such as DocuSign and Adobe Sign are used every day in normal business, which is exactly why they are effective bait. A message saying a document is awaiting your signature carries built-in urgency and an expectation that clicking is the correct next step. Legitimate signing platforms themselves maintain guidance warning users to verify links and sign through the official site, and the Australian Cyber Security Centre's social engineering threat overview lists impersonation of trusted brands as a core attack pattern. Scamwatch's guide to spotting and avoiding scams makes the same point: criminals build trust by borrowing the names of services people already use.
The target is the mailbox credential. A fake signing page asks the user to log in to view the document, harvests the password, and often forwards the same email to the victim's own contacts — turning one clicked link into a campaign inside the company. A successful hit on a finance or executive mailbox scales into invoice fraud, which how to train finance teams to spot fake bank portal phishing pages covers in depth.
Start with security awareness training so the verify-first reflex exists before the first real document email lands.
What you'll need
- 20 minutes for the lesson and 10 minutes for the drill.
- A redacted example of a fake e-signature email with the link visible.
- The e-signature platform the organisation actually uses, and its real web address.
- The route for reporting suspicious email.
- Current guidance from the national reporting services on brand-impersonation phishing.
Run the drill as a no-fault exercise. The goal is the checking habit, not a named suspect.
Step 1: Name the attack
Show the pattern: an email claiming a document awaits signature, often from someone the recipient does business with, with a link that opens a login page. The page is the trap; the document may not exist at all. Some versions arrive as replies inside a real email thread stolen from a colleague's compromised mailbox, which makes them far harder to dismiss.
Expected outcome: Staff can describe the pattern in one sentence. Common mistake: Judging the email by the sender name rather than where the link goes.
Step 2: Name the tells
Walk through the five tells: an unexpected document; a deadline; a sender address that is close to, but not, the real company's domain; a link that does not match the claimed service; and a login page appearing before any document is shown. A real signing platform shows the document preview first and asks for authentication only when the signer acts.
Expected outcome: Staff can find all five in the example email. Common mistake: Trusting the page because it shows the correct logo.
Step 3: Teach the check-first response
The response is never to log in from the emailed link. Staff go to the signing platform by typing its official address, and look for the document in their own account. If nothing is waiting, the email is fake. If a real document is genuinely waiting, signing it there is safe.
The check costs less than a minute and defeats every version of the scam, because the criminals control the link but not the signer's actual account.
Expected outcome: Staff describe opening the platform directly rather than the link. Common mistake: Forwarding the email to a colleague to ask if it looks real, spreading the trap.
Step 4: Rehearse the scenario
Run a two-minute drill. The learner receives an email: contract awaiting signature, expires today, from a supplier's slightly misspelled domain, with a login page behind the link. The learner does not click, opens the platform from its official address, finds no document, and reports the email.
Phishing simulations carry the same scenario safely, and rotating the pretext between contracts, HR forms and supplier agreements keeps the drill honest.
Expected outcome: The learner completes check-then-report without entering any credentials. Common mistake: Making the fake login page the whole lesson instead of the link-checking habit.
Step 5: Cover the reply-chain variant
Show a version that arrives inside a genuine email thread, using a real colleague's signature and tone. The lesson is unchanged: the destination of the link decides, not the thread or the sender. Anyone unsure replies to the colleague through a known channel — a call or chat — rather than the email.
Expected outcome: Staff verify out-of-band before acting on a threaded request. Common mistake: Treating a real thread as proof the link is real.
Step 6: Capture the report
A useful report includes the sender address, the claimed document and a screenshot without clicking. If credentials were entered, the password changes immediately on every account that reuses it, and IT checks for unauthorised mailbox rules — the first thing attackers add to hide their trail.
Make reporting one click from the inbox. Cyber Aware phishing simulations include a report button so the same reflex carries into real incidents.
Expected outcome: Reports reach security within minutes; exposed passwords change within the hour. Common mistake: Changing only the compromised account's password when the same password is reused elsewhere.
Step 7: Target the follow-up
E-signature phishing concentrates on roles that sign: executives, managers, HR and finance. Use human risk reporting to see which teams reported quickly and re-brief the rest, rather than sending one blanket reminder.
Expected outcome: Refreshers reach the signing roles first. Common mistake: Assuming technical staff need the lesson and everyone else does not.
Troubleshooting
Someone already entered their password
Change the password immediately from a clean device, check mailbox rules and recent sign-ins, and report the incident through the agreed route. Do not blame the reporter; the next report depends on this one being handled well.
The email arrives inside a real thread
The thread may be genuine and the link stolen with the mailbox. Verify with the colleague by call or chat before any click, and let security review the original message.
The platform is one the team rarely uses
The rule does not change: open the platform by typing its official address. Rarely-used services are the easiest to fake precisely because staff do not know their real address.
Staff cannot tell lookalike domains apart
Teach them not to judge. The check-first rule — open the platform directly — works without reading any domain at all.
Tools and resources
- A one-page card: don't sign from the email, check the platform directly.
- Redacted drill emails for contract, HR-form and supplier-agreement variants.
- Current national reporting guidance on brand-impersonation phishing.
- Cyber security gap assessment for mapping verification and reporting controls to wider obligations.
What to do next
Run the e-signature scenario once in the next 30 days and measure how fast the email gets reported rather than opened. Under 10 minutes is a workable 2026 benchmark; use the result to set the next training reminder.
FAQ
What is a fake e-signature phishing email?
It is a message impersonating a signing service, linking to a page that steals the recipient's email credentials before any document is shown.
How do I check whether a signing email is real?
Open the signing platform by typing its official address and look for the document in your account. Nothing waiting means the email is fake.
Why do scammers want email passwords rather than document contents?
A mailbox is the master key: it enables invoice fraud, further phishing to colleagues and access to sensitive threads. The fake document is only the lure.
What should staff do if they clicked the link and logged in?
Change the password immediately from a clean device, check for unauthorised mailbox rules, and report to security without waiting.
Can a real e-signature email ever ask for a login first?
Reputable platforms show document details before authentication. A login wall with no document context is a strong phishing signal.
How often should e-signature phishing training run?
Twice a year, refreshed whenever a signing platform is in active use for a major deal round, because that is when campaigns peak.
One last thing
The scam only needs one click and one login. The counter-move is smaller than the scam: type the platform's address yourself, and the whole trap disappears.