If you received a request to sign a document through Sign.Plus that you weren't expecting or don't trust, here's what to do.
What to do now
- Don't open attachments, click links, or sign anything.
- Forward the whole email to security@alohi.com with the subject Security incident reporting.
- Delete it from your inbox.
You don't need a Sign.Plus account to report it.
Why you received it
Sign.Plus is used by many businesses to send documents for signature. A signature request is sent by the person or company named in the email, not by Alohi. If someone misuses Sign.Plus to send you a fake invoice, order or "important document", your report lets our security team investigate and take action against the sender's account.
Signs a request may not be genuine
- You don't know the sender, or weren't expecting a document from them.
- The email has an attachment. Sign.Plus signature requests never include attachments. A PDF is only attached once everyone has signed.
- It pushes you to act fast, asks for payment, or asks for passwords or card details.
- The document doesn't match the message, for example an "invoice" from a company you don't do business with.
If in doubt, contact the sender through a channel you already know before opening anything.
How to send a useful report
- Forward the original email rather than only a screenshot - its technical details help us trace the sender.
- Add the date and time you received it.
- If others in your organization may have received it too, let them know not to open it.
For other security concerns, such as emails or websites pretending to be Alohi, see Security incident reporting: How can I address potential threats?