A payment authorization is the kind of mail a finance desk actually opens, because DocuSign is a name contracts already know and a waiting signature is a line someone expects when a vendor is about to get paid. The subject in this case asks you to complete with Docu-Sign, names a file called Thomas.pdf, and then asks you to please sign. That combination is enough of a signature request to survive the few seconds between the inbox list and the reading pane.
The body writes as a DocuSign Payment Authorization Notice, greets you as Dear Thomas, and says a Payment Authorization Document has been securely shared with you via DocuSign. It tells you the document requires your review and signature to confirm authorization of the payment terms outlined, then it asks you to complete the authorization promptly to avoid delays in processing. A single control sits under that hurry and is labeled Review and Authorize Payment, which is the only action the card offers besides a footer that talks like a product. The footer talks about secure delivery, encrypted information, and a Support Center, and it even says the message was generated automatically, which is how paperwork talks when it wants to sound like a system instead of a stranger.
If you need to know whether anyone actually sent you a payment document, you check the thread you already have with that person, or you open the signing product the way you already do. A real authorization, when one exists, is still sitting in the envelope you already use, and it will still be there after you leave this letter alone.

Overview
The letter wants you to treat a payment authorization as a document you must sign right now, then it uses a Review and Authorize Payment button to choose the next page for you. That next page copies a mail login and asks for the password you already use at work, which is the harvest the payment story was written to hide. What they take first is the login for the inbox you are sitting in, and after that they take the inbox itself. That includes the threads with vendors, the reset codes that land an hour later, and the people who already answer when your name is on the From line. The payment terms story is costume for that harvest, because an authorization that might delay processing is the kind of errand a tired desk will finish before asking whether DocuSign actually sent the note.
DocuSign remains a real company with a real signing product, and that fact is why the name is useful on a From line. Anyone can type DocuSign Payment Authorization Notice into a display name, which means a tidy heading does not prove that a document was shared or that anyone asked you to confirm payment terms from this message. People who steal inboxes borrow letterhead from software that already sounds like contracts, signatures, and money moving, because they want you to treat the note as a chore you already meant to finish.
Official signing lives inside the product after you type docusign.com yourself, on a page you already use rather than on a page a cold letter chose for you. A surprise authorization is a poor substitute for that door, because DocuSign does not collect a mailbox password in order to show you a payment document. If a later page also asks for a code from your phone, they will take that too, since the login is what they designed the authorization around.
The Federal Trade Commission describes this shape in ordinary language in How To Recognize and Avoid Phishing Scams, where it says scammers use email to steal passwords, account numbers, or Social Security numbers. A common story, the Commission adds, is a problem with an account when there is no problem, or a document you must confirm when you do not. The Commission’s advice is to contact the company with a phone number or website you already know is real rather than with the information in the email. A Review and Authorize Payment button that arrived inside an unexpected authorization notice is information in the email, which is why it is a poor place to start a signature.
CISA says the same thing from the systems side on Avoiding Social Engineering and Phishing Attacks, where it tells people not to reveal personal or financial information in email, and not to follow links sent in email when a message asks for that information. On Teach Employees to Avoid Phishing, CISA tells staff that if a message feels off, they should verify it without using any phone number or link in the message, which means using a number you already have and a site you already type. That habit is the opposite of fetching a payment document from a letter you did not request, and it is the opposite of typing a mailbox password so an authorization can supposedly finish loading.
Review and Authorize Payment is the click
Read the button the way a tired controller reads it between two other alerts, because Review sounds like a document you already own and Authorize Payment sounds like money that is already in motion. The subject has already done the signature request, the shared document line has already done the paperwork, and the delay warning has already done the calendar, so by the time your eye hits the rectangle the errand feels mostly finished.
A real DocuSign envelope does not need that rectangle in a surprise email, because if a payment document actually landed, it would already be visible after you open the product yourself. What the button actually does is take you off the inbox and onto a page the sender controls, and on a phone, where hovering is awkward, many people never see the real destination before the next page fills the display.
Payment terms are doing borrowed work
Keep the names straight, because the campaign depends on mixing them up: DocuSign exists, workplaces already use it to close paper, and a payment authorization is a believable thing to put next to a file named Thomas.pdf. Dear Thomas, a claim that a document was securely shared, and a warning about delays in processing are doing the work a real envelope usually does, so a finance person can picture a vendor waiting without checking whether anyone at DocuSign issued that file. Those details can be typed by anyone who has seen a signature request, and matching them to a real envelope is work the letter hopes you will skip because the filename already looks filed.
Display names are cheap, and anyone can set a From line to read DocuSign Payment Authorization Notice, just as anyone can paste a secure-delivery sentence under a yellow bar and date the whole thing on a Monday morning. Microsoft’s guide to spotting phishing tells you to treat mismatched senders as a warning and to slow down when a message wants an immediate click, and a footer that hurries you toward an authorization is that kind of click. Do not reply to ask whether the payment document is real, because a reply teaches them the inbox is live and it lands wherever they pointed the return path. Do not call a number that appears only in the letter, and if you actually use DocuSign, open the product you already use and look for the envelope there.
The next page copies a mailbox login
After Review and Authorize Payment, the story changes, because the inbox promised a payment document while the next screen promises a sign-in. It is built to look like the mail service you already use, so a Gmail address often sees a page dressed as Gmail, a Microsoft address often sees a page dressed as Outlook or a work portal, and other providers get the costume that matches their own mail. Your address may already be sitting in the box, the colors look familiar, and the language is the language you see every morning, which is how a careful person finishes a login they never meant to start.
A padlock in the browser does not fix that, because encryption only means the path is private and does not mean the person at the other end is Google, Microsoft, or DocuSign. HTTPS can wrap a stolen password as neatly as a real one, and an accurate logo is not a certificate, so you trust the complete domain and the way you reached it rather than the artwork inside the page. Google’s advice on phishing in Gmail is blunt on this point: Gmail will not ask you for your password over email, and if an authorization click then presents a login, you should not type it.
Do not finish that form to see whether a payment file then appears, because a copied sign-in does not become safer when you only wanted to confirm terms. Open a new tab, type the mail service you already pay or open the app you already installed, and look at the account from the inside, since a mailbox that is truly yours will still be there and a fake authorization will not. If you already typed the password, treat it as burned even if the window now says the document cannot be opened, because a dead tab is not proof the letter was harmless.
How The Scam Works
1. An authorization notice lands
It arrives in the same Outlook or Gmail you already trust, wearing a subject that asks you to complete with Docu-Sign, names Thomas.pdf, and then asks you to please sign a DocuSign Payment Authorization notification. The display name presents itself as DocuSign Payment Authorization Notice, and the whole note is built to fit on a phone screen as a courtesy a finance person already expected rather than as a midnight threat to delete the mailbox.
If you are already signed in to webmail, the folders on the left and the search bar on the top make the fake note feel native, because you are not visiting a strange site yet and you are only reading mail. The letter only has to survive the few seconds between the subject and Review and Authorize Payment, and a file named Thomas.pdf next to payment terms is enough to buy those seconds inside a finance folder.
2. The name copies DocuSign
DocuSign belongs to a real product that workplaces already use to close paper, and that fact is the load-bearing detail in a letter that only has a few seconds to look like a signature request. When you have ever countersigned a vendor packet, forwarded an envelope, or seen DocuSign on a closing checklist, you fill in the rest yourself, and even if you have never opened the product, the phrase payment authorization still sounds like money.
The people who wrote the letter did not need to sit inside DocuSign to borrow a Payment Authorization Notice heading, a securely shared sentence, and a Support Center line that would survive a five-second glance. The thief is only inside your inbox if the authorization click works, which is why the name on the letter is doing borrowed work rather than proving a document was shared.
3. A payment waiting is the hurry
Please complete the authorization promptly to avoid delays in processing is doing the work a late invoice usually does, because money that might stall is a Monday a finance person already fears. A signature can wait until after lunch when it is only paper, but a payment that might miss a window feels like a problem that grows while you hesitate, which is why the letter puts delay next to the only button that works.
Finance teams live on that kind of clock, because vendors send reminders, controllers ask for dates, and a late authorization that posted without a conversation is a real kind of afternoon. The lure is borrowing that afternoon, and it does not need a long pitch when it can offer a filename, a shared-document line, and a processing delay that a tired person can already imagine matching to last week’s vendor.
4. Review and Authorize is the handoff
You click Review and Authorize Payment because that is what an authorization notice is for, and because delay is a word that makes a payment line feel like an errand you should finish before lunch. Then the next page asks you to sign in as if you were opening mail instead of showing a signature packet with payment terms in the title bar.
That request is the tell, because you are already in mail, and a real authorization would open inside the product after you typed it yourself rather than asking you to prove you are you so you can see a file the sender already claimed was waiting. CISA’s advice is not to follow a link in a message that then asks for that kind of information, and Review and Authorize Payment is the detour, because the button is a handoff from a letter you trust to a page you should not.
5. The page copies webmail
The page that follows is dressed as the provider you already use, often with the same colors, the same Sign in label, and the same field for the work address or the personal one. The costume changes with the mailbox, so Gmail users get a Gmail-shaped door and other users get the door that matches their own mail, and familiar is the point of that costume. In this run the next page sat on an EdgeOne host, a CDN-shaped name that is not the signing product and is not your mail provider.
Do not finish that form to see whether it is real, because a copied login does not become safer when you only wanted a payment document. Do not send the live button to a coworker so they can check the file, and if you need a second pair of eyes, send a screenshot with the link unclicked or send the raw message as an attachment to a person you already know.
6. They want the mailbox password
If you type the password they have the first key, and if a text, an authenticator prompt, or an email code arrives while that tab is still open they want the second key too. The story will sound helpful, asking you to confirm so the document can load, approve so the secure file can open, or enter the code to verify your work account, and each line is the same request for access to the mailbox you were already sitting in. The payment authorization was never sitting behind that box, because the mailbox was, and the people who wrote the letter designed the shared-document line so you would not notice the swap.
Microsoft’s phishing page tells you to change the password on every affected account if you think you typed it on the wrong site, and to turn on multifactor authentication if it is not already on, which is the same advice the FTC gives in consumer language. Once they can open the account they are not hunting for a Thomas.pdf payment file, because they are reading the last invoice you sent, the last invoice you received, and the thread with a vendor who pays by wire, and then they write the next message in your voice. A compromised mailbox is not a nuisance in that setting, because it is a way to move a payment without ever calling you again.
7. A second crew sells recovery
The last move is often social, and it may not even be the same people, because a day later you can get a call, a text, or a fresh email that already knows you opened a DocuSign authorization. They will offer to lock the envelope, pull the payment document, or stop a transfer you never approved, and then they will ask for a code, a remote-access session, a second password, or a cleanup fee. Hang up, because a stranger who found you is not your incident responder, and a DocuSign security desk that called you after Review and Authorize Payment is not DocuSign.
That is why a quiet admission that you already clicked, even if you did not pay anyone, is not the end of the story, because you may not have paid while the person who trusts you might. Tell the people who send you money and the people you pay, and tell a real coworker, if you actually share a closing, on a number you already have rather than on a number that arrived after Review and Authorize Payment. A 30-second call from you is cheaper than a week of wires that look like your week, and the second crew is counting on shame to keep you quiet long enough for the first crew’s mail to land.
What To Do If You Have Fallen Victim to This Scam
If you only opened the email and closed it, you are not finished, but you are not doomed, and if you pressed Review and Authorize Payment and then typed, treat the account as touched and move in this order. Speed beats waiting to name the exact kit they used, because the goal is to take the mailbox back before someone else sends the next invoice in your name. Write down what you remember before the details fade, then stay on official pages you open yourself rather than on anything that arrived inside the authorization letter.
- Write down what you typed, including the time and the subject that asked you to complete with Docu-Sign, then stop using that tab. Write down whether you entered a password and whether you approved a code or an app prompt, then close the authorization page. Do not keep checking it to see if a payment file appears, and do not forward the live button to a friend so they can look. Send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know.
- Open your real mail yourself in a new tab you type, then change the password to one you have not used anywhere else. Use the official site or the app you already trust, and do not return to the authorization letter for a reset link. If this is a Microsoft account, follow Microsoft’s steps to recover a hacked or compromised Microsoft account. If you cannot sign in, use the official reset path, and if this is Gmail or a workplace portal, open that product the same way, from an address you typed.
- Sign out of other sessions everywhere you can, then turn multifactor authentication back on before you do anything else with the mailbox. Review recent activity and sign out of sessions you did not start, and if you approved a prompt you did not begin, assume that session is not yours until you kill it, and remove recovery phones and recovery addresses you did not add. A password change that leaves an old session running is only half a change, and if you reuse that password on banking, payroll, or the signing product, change those on their own sites too, after you type those sites yourself.
- Look for inbox rules, automatic forwarding, and mail that left without you, because those are the quiet ways a stolen mailbox keeps working after a password change. Check the Sent folder and look for a new mailbox delegate, a new app that can read mail, or a filter that hides replies. Delete what you did not create, search for other payment authorization notices you did not expect, and if this is a work account, call IT before you spend an hour hunting, because they can dump sessions and pull the audit faster than you can.
- Call the people who pay you and the people you pay, using a number from last year’s invoice, a card in the drawer, or a listing you already trust. Tell them a fake DocuSign authorization tried to take the mailbox, so they should not honor a new account number or a rushed updated-wiring note that arrives this week. If you actually share a closing or a vendor file, say that out loud on a number you already have, because the lure picked a payment name for a reason. A coworker who already paid according to this letter still needs a human check in the real product.
- Tell the bank the same day if invoices, payroll, or deposit files live in that inbox, and ask them to watch for a change-of-account request. Call any payroll or processor vendor as well, because a charge you did not make and a transfer you approved because a message looked like you are different problems, and time still matters on both. Do not invent a dollar figure for a loss you have not seen, and report what you actually typed and what you actually see on the statement. If you use DocuSign and a real envelope is waiting, open that product yourself and look there, not in this email.
- Report the email through the controls your mail product already publishes, then scan the device if Review and Authorize Payment saved a file or pushed a viewer. In Outlook, use Report and then Report phishing, the path Microsoft publishes on its phishing help page, and in Gmail use Google’s reporting control from the same phishing help page they publish for this. Forward a copy to the Anti-Phishing Working Group at reportphishing@apwg.org, then file the same facts at the FTC’s ReportFraud site and, if you want a law-enforcement copy, at the FBI’s IC3. If a password, a bank account, or a Social Security number went into that page, use IdentityTheft.gov for the next steps. If a file landed, run a full scan with Malwarebytes or the antivirus you already keep updated, remembering that the scan does not get a password back and the password change does that.
If someone forwarded you the note, send them this page instead of the Review and Authorize Payment button, because these authorizations travel in office threads when they look like work, which is part of how they move. Do not install a new cleaner you just searched for because a follow-up email recommended it, since that search is how people add a second problem. The recovery call that already knows the subject line belongs to the same family as step seven above, so hang up and stay on the official path you opened yourself.
If you use DocuSign every day, treat this letter as a reminder to open the product from a bookmark you already keep, not from mail, and look at the real envelopes waiting for a signature. If the product shows no payment document, then no payment document was shared, and if something did land, it will still be there after you ignore Review and Authorize Payment. A fake authorization does not become real because you were waiting on vendor terms, and waiting is the opening they wrote the subject for.
The Bottom Line
A note that asks you to complete with Docu-Sign, names a file called Thomas.pdf, writes as a DocuSign Payment Authorization Notice, claims a payment document was securely shared, warns about delays in processing, and offers Review and Authorize Payment, is a login behind an authorization. The product name belongs to a real company, while the operator of this letter does not, and the click is the door they built so you would type a mailbox password instead of opening the signing product yourself. After that they use the inbox to write as you, and the recovery call that already knows the subject is the second shift.
Open the mail service you already pay by typing it yourself if you need to know whether anything is wrong, and open the signing product the same way, from a site you already type, if you need to know whether a payment document actually landed. If you already typed the password, change it on the provider’s own page, kill the other sessions, and tell the people who send you money before the next email goes out as you. The payment file was never the point of the letter, because the mailbox was what they came to collect.