Skip to main content
ThreatPhishing & impersonation

Fake PandaDoc / Proposify proposal and contract management subscription payment failed, pending proposals and contracts suspended, document templates inaccessible, or electronic signatures at risk phishing

fake-pandadoc-proposify-proposal-contract-platform-billing-phish

What this tier means

High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.

How Gorganizer detects this

Phishing emails impersonating PandaDoc or Proposify claiming the proposal and contract management subscription payment has failed, pending proposals and contracts are suspended, document templates are inaccessible, electronic signatures are at risk, or client approvals are no longer active — directing them to update billing or restore access through a credential-harvesting portal. A distinct attack category targeting proposal and contract platforms where suspension blocks deals from closing at the exact point when contracts are being signed. Key facts: (1) PandaDoc serves 50,000+ customers ($19-59+/user/month, Enterprise much higher) including teams at Autodesk, Verint, and Kforce — PandaDoc is the all-in-one proposal, quote, and contract management platform where sales teams build, send, track, and collect e-signatures on proposals and contracts; a PandaDoc workspace suspension simultaneously makes all in-flight proposal documents inaccessible for both the sender and the recipient — clients who received a proposal link see a 'document not available' error; contracts awaiting a final signature cannot be signed; (2) The 'pending proposals and contracts suspended' hook is acutely urgent at end-of-quarter: sales teams have open deals where the contract is literally in the prospect's inbox waiting for a signature — a PandaDoc suspension means those deals cannot close until access is restored; for a team managing $500K in open contracts, suspension costs that full amount in delayed revenue and risks deal loss entirely if the prospect loses interest; (3) Proposify serves 10,000+ customers ($49-590+/month) with particular strength in agencies, consulting firms, and service businesses that rely on proposals to convert every new client — Proposify proposal templates represent significant design and copywriting investment; a Proposify account suspension makes every proposal template inaccessible and prevents any new proposals from being sent to prospects; (4) The 'document templates inaccessible' hook targets a specific loss: companies build branded proposal templates in PandaDoc/Proposify over months — template library loss is a long-term productivity impact beyond just the immediate deal risk; (5) PandaDoc and Proposify credentials expose the complete sales and pricing strategy: every proposal reveals pricing tiers, discount levels, and contract terms offered to different customer segments — competitive pricing intelligence that reveals the full commercial strategy, plus client contact information from every sent proposal. Warning signs: sender not pandadoc.com or proposify.com; genuine PandaDoc billing at app.pandadoc.com/settings/subscription; Proposify billing at app.proposify.com/account/billing.

False-positive guard

Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.

About the scoring engine

Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.

Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.

Ready to clean your inbox?

Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.

Get started