Dropbox Hack Affects About 5,000 Accounts Through Legacy Lenovo ID

Dropbox Hack Affects About 5,000 Accounts Through Legacy Lenovo ID

Dropbox has disclosed that about 5,000 accounts were compromised in a hack last month through a legacy Lenovo ID integration that lacked two-factor authentication, while new reports detail Teams vishing, phishing kits, a…

Dropbox has disclosed that about 5,000 accounts were compromised in a hack last month, and the company says the unauthorized access was linked to a legacy Lenovo ID integration that did not have two-factor authentication turned on. Dropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, and it terminated all sessions authenticated through a Lenovo ID. Lenovo said the issue relates to a legacy integration between Lenovo ID and Dropbox that could be used to improperly authenticate certain Dropbox accounts. The incident allowed threat actors to view and download content stored on the cloud storage platform, making it a reminder that old integrations with weak or missing second-factor protections can open the door to an entire cloud account.

Microsoft has warned of a separate human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or help desk staff. After gaining trust, the attacker convinces the victim to grant an interactive remote session, then uses remote monitoring and management (RMM) tools to establish control. Microsoft said the attacker uses PowerShell to download and silently install a malicious MSI package, which stages a portable Node.js runtime and an obfuscated JavaScript implant for persistent command execution and command-and-control (C2). The attacker then performs host and Active Directory reconnaissance, captures screenshots, executes follow-on payloads through trusted Windows binaries, and moves across the enterprise over Windows Remote Management toward domain controllers. Separately, Palo Alto Networks Unit 42 reported a coordinated vishing operation called Spring Ring that used external Microsoft Teams accounts to impersonate IT help desk staff. Between January and April 2026, the campaign targeted more than 150 employees across at least 10 companies. Unit 42 said what seems like a benign chat is actually a voice phishing call, and in a more advanced variant attackers transitioned from vishing to an NTLM relay attack aimed at an organization's domain controller. Researchers identified 26 distinct attacker identities behind the chat and call attempts.

Sophos has published new analysis of The Gentlemen ransomware operation, which it tracks as Gold Sherwood. The group claimed a total of 683 victims by the end of July 2026, with 169 victims added in July alone. Sophos described a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, defense evasion, backup disruption, and ransomware deployment. Affiliates use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims. In the phishing-as-a-service world, the Outsider platform remains active despite law enforcement taking down a number of its domains. Group-IB said it identified over 700 new phishing pages created with the kit within a month after Google filed a civil lawsuit against its operators, showing that affiliates continue to use the service. The operator is known as ChenLun. Group-IB said the phishing kits are distributed through a Telegram ecosystem, and operators use a WebSocket connection for live keylogging and to manipulate multi-factor authentication challenges. A separate government-themed tax campaign described by iZOOlogic uses U.A.E.- and India-themed tax assessment lures to persuade recipients to open a malicious disc image. The disc image contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL. This makes DLL sideloading the central mechanism: the malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms, contains three encrypted payloads, and paves the way for a Registry-resident second stage that connects to an external server over UDP. ZeroBEC disclosed details of a turnkey phishing service called BlueKit used to target CEOs of financial-industry groups for credential theft using browser-in-the-middle infrastructure. The campaign uses document-sharing lures and ZeroBot to screen bots, then moves selected victims into a fake document-viewer workflow that delivers a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance. BlueKit is advertised at $250 for seven days, $480 for 14 days, and $940 for 30 days, higher than Tycoon 2FA, Greatness, and Forg365, which cost roughly $350, $289, and $400 per month.

Researchers have analyzed the backend infrastructure of Prince of Persia, a little-known Iranian hacking group tracked by Whisper Security that deploys the Foudre and Tonnerre malware families. According to Kaveh Azarhoosh, the backend is self-authoritative: each live command-and-control server also runs the nameservers for its own domains. The researchers also identified a dormant reserve of 58 domains that are registered and delegated to the group's own nameservers but currently point at no server. Azarhoosh said they are staged, not live, and the moment any one of them gains an address record, a new command server has gone live and is visible before it does anything. Intezer detailed a fake privacy browser downloaded from a counterfeit site after a victim mistyped a domain name, which turns remote attacker commands into simulated mouse and keyboard input. The site was surfaced via a sponsored search result on Google, and the infection began with one simple mistyped letter. Intezer described it as a USB Rubber Ducky attack delivered over the internet, noting that it evades EDR and sits at zero to two detections on VirusTotal. The campaign has been tracked back to a similar operation from January 2016, indicating at least a decade of activity. The U.S. FBI is investigating a new ID theft service called Nexus, which claims to have digital scans of over 153 million driver's licenses from people in the U.S. and Canada. According to independent security journalist Brian Krebs, the service is said to be siphoning images collected by identity verification company IDScan.net. Launched on the dark web on August 31, 2026, Nexus also claims more than 10 million identification cards, over three million travel documents or international IDs, and at least 579,000 medical cards. Each record can be unlocked for $100. Nexus went offline shortly after the exposé was published, and IDscan.net is said to be investigating.

A scan of 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies found llms.txt or llms-full.txt files at the root of their websites alongside robots.txt. An Israeli stealth startup said these files are not a sitemap or disclaimer but a curated instruction set for AI agents: what to read, which APIs to call, which packages to install, and which domains to trust.

How to Protect Yourself

  1. If you get an unexpected call or chat claiming to be from IT support, hang up and call your company's IT desk using a number you already have, not one they give you.
  2. Turn on two-factor authentication for every account that offers it, especially cloud storage and email, so a stolen password is not enough to get in.
  3. Be careful about clicking Allow or entering a code during a remote session; only do it if you started the support request yourself.
  4. Before downloading software, check the web address carefully letter by letter, and avoid clicking sponsored search results; type the official address directly.
  5. If you run a website, ask your developer to check files like llms.txt and robots.txt for any unusual package or domain names that could be malicious.

Terms Explained

  • two-factor authentication An extra login step, such as a code from your phone, that stops someone who knows your password from getting in.
  • vishing Voice phishing, where a caller pretends to be someone you trust to trick you into giving access or installing software.
  • phishing-as-a-service A subscription service that sells ready-made fake login pages and tools to criminals who want to steal accounts.
  • DLL sideloading A trick that places a malicious file next to a trusted program so the program loads the bad file without knowing.
  • command-and-control (C2) A server that attackers use to send instructions to computers they have infected.
  • llms.txt A file on a website that gives AI assistants instructions about what to read or use, which attackers can abuse by naming bad packages.

Related AEU services

  • AEU-I IT and security consulting