Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Phishing pages hosted on Dropbox: the 2024 'BEC 3.0' credential-harvesting wave

September 2024

MediumStatus: Ongoing 5,000+ attacks observed in two weeks (Check Point, Sept 2024) affectedProduct: File sharingYear: 2024

Check Point recorded thousands of attacks in which criminals hosted credential-harvesting documents on Dropbox itself, so the phishing emails came genuinely from [email protected] and sailed past filters that trust the Dropbox domain.

What happened

In September 2024 Check Point's Harmony Email researchers reported observing more than 5,000 attacks in the first two weeks of the month that abused Dropbox to host phishing material. The lure was an authentic Dropbox notification — sent from Dropbox's own systems — telling the recipient a document was waiting. Clicking through led to a real, Dropbox-hosted page (often styled like a OneDrive or Microsoft document) whose 'Get Document' button then redirected the victim to an external credential-harvesting site.

Check Point labeled this 'BEC 3.0': rather than spoofing a brand, attackers ride legitimate services so the email passes SPF/DKIM and reputation checks because it really did originate from Dropbox. Darktrace separately documented a January 2024 case in which 16 users at one organization received a genuine Dropbox link to a PDF that led to a fake Microsoft 365 login, and the resulting logins appeared to carry a valid MFA token — indicating the attackers bypassed the victim's MFA.

Impact

Because the messages genuinely come from Dropbox, this technique neutralizes domain-blocking and brand-impersonation defenses and shifts the burden onto user vigilance and behavioral detection. It illustrates how Dropbox's trusted file-sharing and notification system can be turned into a delivery platform for credential theft and MFA-bypass, harming both Dropbox's brand and downstream Microsoft 365/SaaS accounts.

Dropbox's Response / Official Position

Dropbox provides an abuse-reporting mechanism and takes down shared content and accounts used for phishing when notified, and warns users that it will never ask them to enter unrelated third-party (e.g. Microsoft) credentials via a Dropbox link. The campaigns were surfaced by external security vendors rather than by a Dropbox advisory.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
2 sources
Medium1,180+ documented BBB complainants (3-year window)

Over 1,180 BBB complaints: the paper trail of Dropbox's billing and support grievances

The Better Business Bureau has logged more than 1,180 complaints against Dropbox over three years, dominated by surprise auto-renewal charges, denied refunds, and support tickets that vanish without resolution.

Pricing & Business PracticesAccount Lockouts & Support Failures
Read documentation