TL;DR Attackers sent a convincing DocuSign notification with a "Review & Sign" button that chained through Google Maps redirects to an Amazon S3-hosted credential harvesting page. The redirect chain ...
Another version of the scam claims to be an invoice but does not specify what it is for.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results