What to look out for today
- Dropbox account takeover warnings: some Dropbox users were told their accounts were accessed after a flaw in Lenovo’s email verification process was exploited to create fraudulent Lenovo IDs.
- Freelancer/contractor-targeted phishing with Excel attachments: US authorities charged a Russian national linked to campaigns that sent malware-laced Excel files to large numbers of freelancers via a freelance platform.
- Mobile malware pushed via ads: researchers report an Android trojan (“StreamRat”) promoted to Spanish-speaking users through a fake TV-streaming theme on Meta, with high levels of device control once installed.
Why this matters to smaller businesses
- Dropbox is often a key business system for client files, contracts and HR/finance documents. If an attacker gets in, they may steal data, delete files, or use your account to spread convincing phishing to customers/suppliers.
- SMEs rely heavily on contractors and freelancers (bookkeeping, marketing, IT, design). If their device is infected, your business can be pulled into invoice fraud, credential theft, or shared-file compromise.
- Mobile devices are business devices even when they’re “personal”. A compromised phone can expose email, MFA prompts, authenticator codes, banking apps and messaging used for approvals.
Warning signs
- Dropbox security emails about new sign-ins, new devices, or unrecognised sessions.
- Unexpected password reset emails, or reports that someone “couldn’t log in” and is asking you to click a link urgently.
- Freelancers/contractors forwarding you “client files” as Excel attachments, especially with urgency, payment context, or vague filenames.
- Staff installing “streaming” / “TV” / “free content” apps after seeing ads, then seeing unusual pop-ups, accessibility permissions requests, or battery/data spikes.
- Customers/suppliers receiving odd messages “from you” containing shared links or attachments.
How attackers may exploit the situation
- Supplier identity chain abuse: attackers look for ways to register accounts or bypass verification with a trusted brand, then pivot into other services where that email identity is relied upon.
- Account takeover to business email compromise: access to file stores can reveal invoice templates, approver names, and payment routines, enabling convincing payment-change fraud.
- Attachment-led malware: malware-laced spreadsheets can be used to steal browser passwords, session cookies, and access tokens—then spread to shared drives and mailboxes.
- Mobile remote-control trojans: once installed, criminals may read messages, overlay login screens, intercept MFA, and approve transactions.
What to do today
- Dropbox / file-sharing quick check: review recent sign-ins/sessions, remove unknown devices, and ensure MFA is on for all users (especially admins).
- Contractor safety step: remind contractors you will never require macros-enabled spreadsheets for payments; require shared links over emailed attachments for routine document exchange (where feasible).
- Staff message (5 minutes): warn about “urgent Excel invoice” emails and about installing apps from ads. Encourage reporting, not clicking.
- Mobile controls: check business mobiles (and BYOD if applicable) for risky permissions and ensure OS/app updates are enabled.
- Prepare for disruption communications: if a SaaS outage or security incident happens, have a short internal/external message template ready (what’s affected, what you know, what you’re doing, when next update is due).
Ask your IT provider
- Can you show us a list of Dropbox/SSO admin accounts and confirm MFA and conditional access are enforced?
- Do we have alerting for unusual logins, mass downloads, or new third-party app connections to our cloud storage?
- How are contractor accounts handled (separate identities, least privilege, time-limited access)?
- What protections do we have against malicious attachments (email filtering, sandboxing, blocking macros, safe links)?
- If a key SaaS service is compromised or down, who drafts customer comms and how quickly can we notify staff and clients?
Patch watch - only one short paragraph, and only if relevant
This brief is not a patch drill today. However, given the mobile-malware and attachment themes, make sure your organisation’s devices are set to auto-update (operating system and apps) and that outdated phones/laptops used for work are identified and phased out.
One action today
Send a same-day staff note: “No urgent Excel attachments for payments; report unexpected Dropbox login alerts; don’t install apps from ads,” and include the internal reporting route.
Related Actions On Cyber resource
Actions On Cyber checklist: “Supplier incident & account takeover response (Dropbox/Google/Microsoft) — what to check in the first 30 minutes”
Sources
- Dropbox accounts breached through Lenovo email verification flaw (BleepingComputer)
- US charges Russian for infecting 80,000 freelancers with malware (BleepingComputer)
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands (The Hacker News)
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control (The Hacker News)
- Communicating Under Pressure: Best Practices for Service Providers (CISA Cybersecurity Advisories)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.