Armenia has appeared among the countries where company employees are receiving fake notifications allegedly sent on behalf of the Zoom and DocuSign services. Fraudsters are using multi-wave campaigns to try to obtain users’ personal and banking data, Kaspersky Lab told TASS.

According to experts, fraudulent emails are being distributed not only in Armenia, but also among employees of companies operating in Russia, Azerbaijan, some other countries in Europe and the Middle East, as well as Latin America.

The first wave was associated with DocuSign, a popular platform for working with electronic documents and digital signatures. In September, Kaspersky Lab specialists had already detected more than a thousand such messages.

The second wave continues to this day. In this case, scammers pose as representatives of the Zoom video conferencing service.

The emails may contain messages that allegedly indicate an upcoming account lockout, or a notification about a received message. The user is tried to open the attached file or click on the respective link.

The attachments, in particular, are disguised as a payment confirmation form. It is proposed to indicate the company name, email, country, phone number, and bank card details.

In some cases, scammers do not use an attachment, but place the phishing link directly in the text of the email. Clicking on it can also lead the user to a fake webpage designed to collect confidential information.

Kaspersky Lab did not disclose the start date of the first wave, but noted that the scale of this campaign continues to grow. Experts recommend not clicking on links or opening attachments in unexpected emails—even if the sender seems to be a familiar service.

Particular attention should be paid to requests for banking details and other confidential information, as legitimate service notifications should not require the transmission of bank card details via suspicious forms in emails.