{"success":true,"data":{"id":"adobe-sign-pivot","label":"Fake Adobe Sign / Acrobat Sign document-signing request from non-adobe.com sender","description":"Fake Adobe Sign / Acrobat Sign e-signature document request from a non-Adobe sender. Adobe Sign (rebranded Acrobat Sign) is a widely trusted e-signature platform used for legal, financial, and HR documents. Attackers impersonate Adobe Sign notification emails claiming \"A document has been sent to you for review and signature via Adobe Acrobat Sign — please complete it before the deadline.\" The email links to a credential-harvesting page styled as an Adobe or Microsoft login portal. The pivot attack specifically targets the trusted \"DocuSign-alike\" mental model — recipients habitually click signing links without scrutiny because legitimate documents arrive this way. The signal fires when: (1) body references Adobe Sign / Acrobat Sign / EchoSign brand AND (2) a document-signing or review-and-sign narrative is present AND (3) sender is NOT from adobe.com, adobesign.com, or echosign.com AND (4) no List-Unsubscribe header. Source: GC1 R13 council #6; Proofpoint Adobe Sign phishing 2025; APWG e-sign platform abuse Q1 2026.","tier":"warning","category":"other","isThin":false}}