Ongoing Dropbox credential-theft phishing campaign
Campaign
Summary
Hide ▲
Show ▼
An ongoing phishing campaign is stealing Dropbox credentials from corporate users and can enable account takeover and follow-on fraud. The operation uses urgent-business and procurement-themed emails, PDF attachments, hidden links, and a spoofed Dropbox login page to lure victims. Stolen logins are sent to attacker-controlled Telegram infrastructure, increasing the risk of internal access and misuse.
Related Happenings
Google sponsored search ManageWP phishing campaign
Campaign
H score13
First: 07.05.2026 00:36
Last: 07.05.2026 00:36
Sources 1
About this happening:
A phishing campaign is abusing Google sponsored search results to impersonate ManageWP and steal login credentials, 2FA codes, and account access. The operation ma...
Google sponsored search ManageWP phishing campaign
CampaignAbout this happening: A phishing campaign is abusing Google sponsored search results to impersonate ManageWP and steal login credentials, 2FA codes, and account access. The operation ma...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive Guidance
H score41
First: 09.04.2026 17:02
Last: 09.04.2026 17:02
Sources 1
About this happening:
Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive GuidanceAbout this happening: Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Storm infostealer server-side decryption activity
Malware Activity
H score18
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Storm infostealer server-side decryption activity
Malware ActivityAbout this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Telegram-linked Digital Lutera Android payment-fraud campaign
Campaign
H score40
First: 17.03.2026 18:30
Last: 17.03.2026 18:30
Sources 1
About this happening:
A Telegram-linked Android payment-fraud campaign is actively coordinating access attempts and sharing intercepted login data, increasing the risk of account takeover and f...
Telegram-linked Digital Lutera Android payment-fraud campaign
CampaignAbout this happening: A Telegram-linked Android payment-fraud campaign is actively coordinating access attempts and sharing intercepted login data, increasing the risk of account takeover and f...
Fake shipment tracking SMS phishing campaign
Campaign
H score35
First: 16.03.2026 16:45
Last: 16.03.2026 16:45
Sources 1
About this happening:
A global surge in fake shipment tracking phishing campaigns is stealing funds and credentials at scale, with activity rising from almost none in 2024 to over 100 cam...
Fake shipment tracking SMS phishing campaign
CampaignAbout this happening: A global surge in fake shipment tracking phishing campaigns is stealing funds and credentials at scale, with activity rising from almost none in 2024 to over 100 cam...
Timeline
-
02.02.2026 02:00 2 articles · 5mo ago
Forcepoint warns of Dropbox credential-phishing campaign
Initial DisclosureForcepoint X-Labs warned that an ongoing multi-stage phishing campaign is targeting corporate Dropbox users with procurement-themed emails, PDF attachments, hidden AcroForm links, and a spoofed Dropbox login page to steal usernames and passwords. The delivery chain is designed to bypass SPF, DKIM and DMARC checks, route victims through a legitimate-looking ‘Trusted Cloud Storage’ page, and send stolen credentials to a Telegram channel operated by the attackers for possible account takeover and follow-on fraud.
Show sources
- New Password-Stealing Phishing Campaign Targets Corporate Dropbox Credentials — www.infosecurity-magazine.com — 03.02.2026 12:55
- New Password-Stealing Phishing Campaign Targets Corporate Dropbox Credentials — www.infosecurity-magazine.com — 03.02.2026 12:55