<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333">All,
<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333">DocuSign has admitted they were the victim of a data breach that has led to massive phishing attacks which used exfiltrated DocuSign information.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333">They discovered the data breach when on May 9, 15, and 17 DocuSign, customers were being targeted with phishing campaigns.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333">"Hackers have stolen the customer email database of DocuSign, the company that allows companies to electronically sign documents. These criminals are now sending phishing emails
that look exactly like the real DocuSign ones, but they try to trick you into opening an attached Word file and click to enable editing. Here are some of the subject lines:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial","sans-serif";color:#333333">Completed: [domain name] – "Wire transfer for recipient-name Document Ready for Signature"<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial","sans-serif";color:#333333">Completed [domain name/email address] – "Accounting Invoice [Number] Document Ready for Signature"<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial","sans-serif";color:#333333">Subject: “Legal acknowledgement for [recipient username] Document is Ready for Signature”<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial","sans-serif";color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial","sans-serif";color:#333333">It is recommended that you filter or delete any emails with these specific subject lines.</span><span style="font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";color:#333333">The campaigns all have Word docs as attachments, and use</span><span style="color:#333333"> </span><span style="font-family:"Arial","sans-serif";color:#333333"><a href="https://www.knowbe4.com/what-is-social-engineering/" target="_blank"><span style="font-family:"Calibri","sans-serif";color:#333333;text-decoration:none">social
engineering</span></a></span><span style="color:#333333"> </span><span style="font-family:"Arial","sans-serif";color:#333333">to trick users into activating Word's macro feature which will download and install malware on the user's workstation.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Arial","sans-serif";color:#333333"><br>
But if you do that, malware may be installed on your workstation. So if you get emails that look like they come from DocuSign and have an attachment, be very careful. If there is any doubt, pick up the phone and verify before you electronically sign any DocuSign
email. Remember: Think Before You Click." <br>
<br>
Let's stay safe out there. </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><i><span style="font-size:10.0pt;font-family:"Arial","sans-serif";color:blue">Barbara McCrary</span></i><i><span style="font-size:12.0pt;font-family:"Times New Roman","serif""><br>
</span></i><span style="font-size:7.5pt;font-family:"Arial","sans-serif"">Chief Information Security Officer<br>
<i>MCSE, MCSE:Security, +Messaging</i>,<i> CompTia:Security+</i></span><span style="font-size:12.0pt;font-family:"Times New Roman","serif"">
</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""><a href="mailto:bmccrary@osrhe.edu"><i><span style="font-size:7.5pt;font-family:"Arial","sans-serif";color:blue">bmccrary@osrhe.edu</span></i></a></span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Arial","sans-serif""> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy">Protecting data is a shared responsibility!</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:8.0pt;font-family:"Arial","sans-serif""> </span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy">INSTALL antivirus and antispyware software.</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy">USE strong passwords.</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy">KNOW who you are dealing with online.</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy">STORE confidential and sensitive data on encrypted devices only.</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy">SHUT DOWN home computers or disconnect from the Internet when not in use.</span><o:p></o:p></p>
<p class="MsoNormal"><span lang="EN" style="font-size:7.5pt;font-family:"Arial","sans-serif";color:navy"> </span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:7.5pt;font-family:"Arial","sans-serif"">Oklahoma State Regents for Higher Education<br>
655 Research Parkway</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:7.5pt;font-family:"Arial","sans-serif"">Suite 200</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:7.5pt;font-family:"Arial","sans-serif"">Oklahoma City, OK 73104</span><br>
<span style="font-size:7.5pt;font-family:"Arial","sans-serif"">405 225.9316 office<br>
405 234.4321 cell<br>
405 234.4588 fax</span> <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:7.5pt;font-family:"Arial","sans-serif"">Note: This communication and attachments, if any, are intended solely for the use of the addressee hereof. In addition, this information and attachments, if any, may contain
information that is confidential, privileged and exempt from disclosure under applicable law,</span>
<span style="font-size:7.5pt;font-family:"Arial","sans-serif";color:black">including, but not limited to, the Privacy Act of 1974</span><span style="font-size:7.5pt;font-family:"Arial","sans-serif"">. If you are not the intended recipient of this information,
you are prohibited from reading, disclosing, reproducing, distributing, disseminating, or otherwise using this information. If you have received this message in error, please promptly notify the sender and immediately, delete this communication from your
system.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>