Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

SMB Cyber Intelligence Brief — account takeover risk, freelancer phishing, and mobile malware via social ads

What small and medium-sized businesses should look out for today.

Moderate Wednesday 02 September 2026, 17:34 UK time
Today’s look-out: Supplier identity/account takeovers + attachment phishing + mobile malware promoted in ads

What to look out for today

  • Dropbox account takeover warnings: some Dropbox users were told their accounts were accessed after a flaw in Lenovo’s email verification process was exploited to create fraudulent Lenovo IDs.
  • Freelancer/contractor-targeted phishing with Excel attachments: US authorities charged a Russian national linked to campaigns that sent malware-laced Excel files to large numbers of freelancers via a freelance platform.
  • Mobile malware pushed via ads: researchers report an Android trojan (“StreamRat”) promoted to Spanish-speaking users through a fake TV-streaming theme on Meta, with high levels of device control once installed.

Why this matters to smaller businesses

  • Dropbox is often a key business system for client files, contracts and HR/finance documents. If an attacker gets in, they may steal data, delete files, or use your account to spread convincing phishing to customers/suppliers.
  • SMEs rely heavily on contractors and freelancers (bookkeeping, marketing, IT, design). If their device is infected, your business can be pulled into invoice fraud, credential theft, or shared-file compromise.
  • Mobile devices are business devices even when they’re “personal”. A compromised phone can expose email, MFA prompts, authenticator codes, banking apps and messaging used for approvals.

Warning signs

  • Dropbox security emails about new sign-ins, new devices, or unrecognised sessions.
  • Unexpected password reset emails, or reports that someone “couldn’t log in” and is asking you to click a link urgently.
  • Freelancers/contractors forwarding you “client files” as Excel attachments, especially with urgency, payment context, or vague filenames.
  • Staff installing “streaming” / “TV” / “free content” apps after seeing ads, then seeing unusual pop-ups, accessibility permissions requests, or battery/data spikes.
  • Customers/suppliers receiving odd messages “from you” containing shared links or attachments.

How attackers may exploit the situation

  • Supplier identity chain abuse: attackers look for ways to register accounts or bypass verification with a trusted brand, then pivot into other services where that email identity is relied upon.
  • Account takeover to business email compromise: access to file stores can reveal invoice templates, approver names, and payment routines, enabling convincing payment-change fraud.
  • Attachment-led malware: malware-laced spreadsheets can be used to steal browser passwords, session cookies, and access tokens—then spread to shared drives and mailboxes.
  • Mobile remote-control trojans: once installed, criminals may read messages, overlay login screens, intercept MFA, and approve transactions.

What to do today

  • Dropbox / file-sharing quick check: review recent sign-ins/sessions, remove unknown devices, and ensure MFA is on for all users (especially admins).
  • Contractor safety step: remind contractors you will never require macros-enabled spreadsheets for payments; require shared links over emailed attachments for routine document exchange (where feasible).
  • Staff message (5 minutes): warn about “urgent Excel invoice” emails and about installing apps from ads. Encourage reporting, not clicking.
  • Mobile controls: check business mobiles (and BYOD if applicable) for risky permissions and ensure OS/app updates are enabled.
  • Prepare for disruption communications: if a SaaS outage or security incident happens, have a short internal/external message template ready (what’s affected, what you know, what you’re doing, when next update is due).

Ask your IT provider

  • Can you show us a list of Dropbox/SSO admin accounts and confirm MFA and conditional access are enforced?
  • Do we have alerting for unusual logins, mass downloads, or new third-party app connections to our cloud storage?
  • How are contractor accounts handled (separate identities, least privilege, time-limited access)?
  • What protections do we have against malicious attachments (email filtering, sandboxing, blocking macros, safe links)?
  • If a key SaaS service is compromised or down, who drafts customer comms and how quickly can we notify staff and clients?

Patch watch - only one short paragraph, and only if relevant

This brief is not a patch drill today. However, given the mobile-malware and attachment themes, make sure your organisation’s devices are set to auto-update (operating system and apps) and that outdated phones/laptops used for work are identified and phased out.

One action today

Send a same-day staff note: “No urgent Excel attachments for payments; report unexpected Dropbox login alerts; don’t install apps from ads,” and include the internal reporting route.

Related Actions On Cyber resource

Actions On Cyber checklist: “Supplier incident & account takeover response (Dropbox/Google/Microsoft) — what to check in the first 30 minutes”

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.