Dropbox A.I CyberSecurity Scoring
Dropbox
Company Information
Website:http://www.dropbox.com
Employees number:3,776
Number of followers:458,587
NAICS:5112
Industry Type:Software Development
Homepage:dropbox.com
Dropbox Risk Score (AI oriented)
Between 0 and 549
DropboxSoftware Development
Updated:
07/09/2026
07/09/2026
544/1000
Critical
C
Dropbox Global Score (TPRM)
xxxx
DropboxSoftware Development
Score locked

DropboxCritical
Current Score
544C (CRITICAL)
01000
9 incidents
-30.57 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
550
SEPTEMBER 2026
562
Cyber Attack
07 Sep 2026 • Dropbox
Dropbox, CurseForge and Modrinth: Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
Malicious Minecraft Mod Deploys Myth Stealer 3.2-FIX in Sophisticated Cyberattack
544
MEDIUM-18
CURRINDRO1788769843
Malicious Minecraft Mod Deploys Myth Stealer 3.2-FIX in Sophisticated Cyberattack
A trojanized Minecraft optimization mod, disguised as a companion to the legitimate Lithium performance mod, has been distributing Myth Stealer 3.2-FIX a password-stealing malware with remote-access, surveillance, and victim-harassment capabilities. The malicious archive, tracked as MythStealer.jar, impersonates Lithium Extras 0.15.0+mc1.21.1 by a developer named "soder," leveraging the reputation of CaffeineMC’s open-source Lithium project to appear trustworthy.
The counterfeit mod initially functions as expected, with 12 of its 13 modules performing legitimate optimization tasks. However, the hidden 13th component delays execution for eight seconds before querying ip-api[.]com for the victim’s public IP and country code, collecting the hostname, and downloading a secondary payload from Dropbox. The downloaded executable, DiscordNitroGenerator.exe, is saved to %APPDATA%\Microsoft\Windows\javaw.exe a path designed to evade detection by blending into systems where Java is commonly used for Minecraft.
The first-stage dropper reports infection progress to a Discord webhook and re-downloads the payload if missing or under 50 MB. At the time of discovery, both the Java archive and the 169 MB executable showed zero detections on VirusTotal, likely due to the campaign’s use of a newly created Discord webhook and seemingly legitimate mod functionality.
The malware bundles a private Java runtime, allowing it to execute even on systems without Java installed. Before launching the payload, the loader displays a fake Windows UAC prompt via PowerShell WinForms, tricking users into granting elevated privileges. The stealer then disables Java bytecode verification, enabling the execution of heavily obfuscated malicious code.
Myth Stealer 3.2-FIX is a Java-based remote-access tool (RAT) with 251 classes hidden in a package named complexer/NUL, exploiting the Windows reserved device name NUL to disrupt analysis tools. Its capabilities include:
- Credential theft: Harvests saved usernames, passwords, payment card details (including CVVs), and browser cookies from Chromium and Firefox-based browsers.
- System profiling: Collects hostname, hardware IDs, OS details, and hardware identifiers via WMI queries.
- Data exfiltration: Steals chat logs, browsing history, and local files, which it can ZIP and exfiltrate.
- Remote control: Enables process hollowing, fileless execution, AMSI bypass, ETW patching, and direct manipulation of the victim’s mouse and keyboard.
- Victim harassment: Includes disruptive functions such as screen rotation, cursor replacement, taskbar hiding, fake error messages, and optical-drive control.
The malware communicates with command-and-control (C2) servers via a custom Netty-based TCP protocol, using RSA-OAEP-protected AES-GCM encryption despite lacking TLS. Researchers identified two C2 configurations: the IP 146[.]19[.]191[.]11 and the domain ays[.]gamepazarin[.]com, which mimics the legitimate Turkish game marketplace gamepazari[.]com.
The campaign highlights how threat actors combine functional game modifications, trusted project impersonation, and social engineering to evade detection. Users are advised to download mods only from verified sources such as Modrinth, CurseForge, or official developer repositories. Indicators of compromise (IOCs) include the SHA256 hashes for MythStealer.jar, DiscordNitroGenerator.exe, and client.jar.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2026
566
Vulnerability
05 Sep 2026 • Dropbox
Magento and Adobe Commerce: Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
Critical Zero-Day Exploit in Magento & Adobe Commerce Under Active Attack (StyleSmuggler)
562
CRITICAL-4
ADO1788668623
Critical Zero-Day Exploit in Magento & Adobe Commerce Under Active Attack
A severe zero-day vulnerability, dubbed StyleSmuggler, is being actively exploited to gain full control of online stores running Magento Open Source and Adobe Commerce. Disclosed by Dutch security firm Sansec on September 5, 2026, the flaw allows unauthenticated attackers to execute remote code (RCE) on vulnerable systems, with attacks confirmed as early as September 4.
The vulnerability affects all current versions of Magento and Adobe Commerce, including the latest 2.4.9 release, and requires no authentication to exploit. Even fully patched stores such as one running 2.4.6-p15 with all July and August 2026 security updates have been compromised, demonstrating the flaw’s severity.
### Exploit Mechanics & Attack Chain
The attack unfolds in two stages, leveraging Magento’s template rendering and email systems:
1. Initial Exploitation – Attackers manipulate "styles" properties in a GraphQL request to inject malicious PHP code into a file Magento generates during normal operations (e.g., payment failure reports).
2. Trigger Execution – The exploit forces Magento to send a "Payment Transaction Failed Reminder" email, executing the poisoned code without requiring the email to be opened or received.
Once triggered, the malware deploys a Rust-based implant (1.9MB, compiled for x86-64 and ARM64) disguised as a Linux kernel thread ([kworker/u:8:0]) to evade detection. The implant persists via a cron job, restarts every five minutes, and avoids standard logging by writing directly to the crontab spool file.
### Evasion & Detection Challenges
- The malware mimics legitimate kernel processes, making detection difficult.
- It modifies its in-memory binary, requiring defenders to hash both the file and live process.
- Some variants avoid external connections, instead querying the site’s Redis instance to steal session data, bypassing network monitoring.
- Sansec’s detection guidance suggests checking `var/report`, but compromised stores have also been found with infections in `var/log/system.log`.
### Mitigation & Response
With no official patch from Adobe as of September 6, store owners are relying on temporary measures:
- Disabling GraphQL for stores not using headless or PWA frontends.
- Unofficial patches from Disrex, ProxiBlue, and Graycore, which harden specific Magento classes but do not fully resolve the vulnerability.
- Server-level protections, such as disabling `proc_open` and mounting temporary directories with `noexec`, to block payload execution.
Adobe’s next scheduled security release is September 8, but there is no confirmation that it will address this flaw. The company has yet to issue an advisory, assign a CVE, or provide an official workaround.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
620
Breach
04 Aug 2026 • Dropbox
Dropbox and Lenovo: Dropbox breach seemingly caused by egregious authentication failure
Dropbox Security Breach Exposes Flaw in Third-Party SSO Authentication
562
CRITICAL-58
DROLEN1788267915
Dropbox Security Breach Exposes Flaw in Third-Party SSO Authentication
Dropbox recently notified multiple users of unauthorized access to their accounts between August 4 and August 21, 2026, stemming from a vulnerability in its single sign-on (SSO) integration with Lenovo IDs. While the company confirmed no files were viewed or downloaded, the incident highlights critical gaps in authentication protocols.
The breach occurred when attackers exploited Lenovo’s flawed email verification process to register Lenovo IDs using victims’ email addresses without requiring inbox access. These rogue IDs were then used to log into Dropbox accounts via Lenovo’s SSO, as Dropbox did not require re-authentication for new identity providers. The attack relied on publicly available email addresses (e.g., from breaches or LinkedIn) and bulk registration tactics, with some fake accounts using disposable names like "John Madden."
Security analysts note that while Lenovo’s verification failure enabled the attack, Dropbox’s lack of secondary authentication for new SSO logins was the primary vulnerability. The company has since patched the flaw and invalidated all sessions linked to Lenovo IDs. The incident underscores risks in federated identity systems when trust in third-party providers is not properly validated.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
619
JUNE 2026
615
MAY 2026
611
APRIL 2026
608
MARCH 2026
620
Cyber Attack
12 Mar 2026 • Dropbox
GitHub, npm, Dropbox and Roblox: Malicious npm Campaign Impersonates Solara Executor to Steal Discord and Crypto Wallet Data
Sophisticated npm-Based Infostealer Targets Windows Users via Malicious Packages
602
MEDIUM-18
DROROBNPMGIT1773476652
Sophisticated npm-Based Infostealer Targets Windows Users via Malicious Packages
On March 12, 2026, JFrog security researchers Guy Korolevski and Meitar Palas uncovered a stealthy cyberattack leveraging the npm ecosystem to distribute the Cipher infostealer. The malware, disguised as a Roblox script executor named "Solara," was embedded in two now-removed npm packages: bluelite-bot-manager and test-logsmodule-v-zisko.
The attack chain began with pre-install scripts in the npm packages, which downloaded a Windows executable from Dropbox. Despite appearing benign on VirusTotal where it evaded nearly all antivirus detection the executable acted as a dropper, concealing a 321MB archive containing obfuscated JavaScript, a full Node.js environment, and an embedded Python script. The payload also included elevate.exe, a legitimate tool repurposed to escalate privileges.
### Discord Account Compromise
Cipher prioritized Discord credential theft, employing two distinct methods:
- BetterDiscord: The malware patched core files to disable webhook protections, ensuring stolen data reached attackers unimpeded.
- Official Discord App: A second-stage payload, downloaded from a live GitHub repository, forced users to log out, then captured credentials, 2FA codes, and credit card details upon re-login. Persistence was achieved by modifying Discord’s installation files to auto-execute the malicious script.
### Browser & Cryptocurrency Theft
The malware conducted a system-wide sweep for sensitive data, targeting:
- Browsers: Chrome, Edge, Brave, Opera, and Yandex stealing passwords, cookies, autofill data, and browsing history.
- Cryptocurrency Wallets: Bitcoin, Ethereum, Exodus, Electrum, and others. It actively decrypted Exodus wallet seed files using local libraries.
- Python Dependency: If Python wasn’t installed, the malware silently downloaded it to ensure successful data exfiltration.
Stolen data was compressed into a ZIP file and transmitted to attackers via file-sharing services or a command-and-control server.
### Response & Mitigation
While the malicious npm packages and Dropbox links have been neutralized, the campaign highlights the risks of supply-chain attacks in open-source ecosystems. The use of obfuscation, legitimate tools (elevate.exe), and multi-stage payloads allowed the malware to evade detection, underscoring the need for vigilance in dependency management.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
699
Breach
10 Mar 2026 • Dropbox
Dropbox and Western Australian Office of the Auditor General: WA government’s Microsoft 365 issues led to $71k being stolen, exposure of child data
Western Australia Audit Reveals Critical Microsoft 365 Security Gaps in State Entities
620
CRITICAL-79
OFFDRO1773174394
Western Australia Audit Reveals Critical Microsoft 365 Security Gaps in State Entities
A recent report by the Western Australian Office of the Auditor General (OAG) uncovered significant vulnerabilities in how state government entities manage their Microsoft 365 (M365) environments, exposing them to heightened risks of cyber incidents, data breaches, and operational disruptions.
The audit identified weaknesses across multiple security domains, including governance, identity and access management, information protection, logging and monitoring, and threat protection controls. Two major incidents highlighted the consequences of these gaps:
1. Data Breach Involving Sensitive Information
An audited entity inadvertently exposed the personal and sensitive data of 32 individuals, including children, by emailing it to an unvetted third-party service provider, which stored the information in Dropbox. The breach stemmed from the absence of data loss prevention (DLP) controls and a failure to assess the third party’s security posture. While some entities had DLP policies in place, they were not consistently applied across OneDrive, SharePoint, Power Platform, Exchange, and Teams, leaving sensitive data unprotected.
2. $71,000 Theft via Phishing and Weak MFA
A threat actor compromised a senior officer’s M365 account through a phishing email, exploiting weak multifactor authentication (MFA). The attack went undetected for a month, during which the attacker:
- Registered their own MFA device
- Created email forwarding rules to conceal communications
- Studied the victim’s email history to craft convincing social engineering tactics
- Submitted a fraudulent invoice, resulting in the theft of $71,000
The OAG attributed the incident to ineffective security configurations, including:
- Failure to block high-risk users and sign-ins
- Lack of email spoofing protections to prevent impersonation
- Insufficient controls to detect and report fake emails from third-party servers
Western Australia’s Auditor-General, Caroline Spencer, emphasized that proper M365 security management is critical for safeguarding government data and ensuring uninterrupted public services amid evolving cyber threats. The findings underscore systemic gaps in third-party risk assessment, DLP enforcement, and phishing defenses across state entities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
717
Cyber Attack
01 Mar 2026 • Dropbox
Dropbox and DocSend: The Hacker’s 2026 Playbook from the Dark Web
ConsentFix Phishing Campaign Exploiting OAuth Tokens in Microsoft 365 Accounts
698
LOW-19
DOCDRO1782743043
New Phishing Tactics Exploit OAuth Tokens in Microsoft 365 Accounts
A sophisticated phishing campaign, dubbed ConsentFix, is targeting Microsoft 365 users by exploiting trusted platforms like Dropbox and DocSend to bypass security measures. Attackers send seemingly legitimate, password-protected lures that evade antivirus detection. Once opened, victims are tricked into dragging a localhost callback link into their browser or executing keyboard shortcuts (e.g., Windows key + R, Ctrl+V), unknowingly handing over OAuth tokens that grant full account access without requiring passwords or multi-factor authentication (MFA).
The attack, first documented on a Russian cybercrime forum in early 2026, was shared as a step-by-step guide complete with code, infrastructure screenshots, and a video tutorial. This "playbook" lowers the barrier for entry, enabling even low-skilled threat actors to launch high-impact attacks. The campaign leverages free services like Cloudflare Pages and Pipedream webhooks to host malicious infrastructure, while LinkedIn and ZoomInfo data is used to tailor phishing lures to specific targets.
Why It Works
ConsentFix exploits routine user behavior, such as clicking through OAuth consent prompts or following familiar sign-in flows. Unlike traditional phishing, victims don’t enter credentials into fake forms instead, they complete what appears to be a legitimate authentication process, inadvertently surrendering session tokens. The attack is fast (under three seconds) and leaves minimal traces, though defenders can detect anomalies like suspicious PowerShell activity or unusual login locations.
Impact
Once compromised, attackers gain access to email, OneDrive, Teams, and other Microsoft 365 resources, enabling data theft, lateral movement, or further phishing campaigns. The technique has evolved from earlier variants like ClickFix, which relied on similar social engineering tactics but with even less technical friction.
The campaign highlights a broader trend: cybercrime as a service (CaaS), where attack methods are packaged and distributed with step-by-step instructions, accelerating the spread of identity-based threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
734
Cyber Attack
02 Feb 2026 • Dropbox
Dropbox and Vercel: Phishing Scam Uses Clean Emails and PDFs to Steal Dropbox Logins
New Phishing Scam Exploits Trusted PDFs and Cloud Services to Steal Credentials
716
CRITICAL-18
DROVER1770065567
New Phishing Scam Exploits Trusted PDFs and Cloud Services to Steal Credentials
Cybersecurity researchers at Forcepoint have uncovered a sophisticated phishing campaign that bypasses traditional email filters by leveraging clean-looking business emails and multi-stage deception. The attack begins with a seemingly legitimate message often referencing a "tender" or "procurement" deal containing a harmless PDF attachment. Unlike typical phishing attempts, the email itself contains no malicious links, relying instead on the PDF to initiate the scam.
The PDFs exploit technical features like AcroForms and FlateDecode to embed hidden clickable buttons, tricking users into interacting with what appears to be a standard document. Once clicked, the victim is redirected to a second file hosted on Vercel Blob storage, a legitimate cloud service that helps the attackers evade security blocks. This file then directs users to a fake Dropbox login page, meticulously designed to mimic the real platform.
Behind the scenes, a script harvests email credentials, passwords, IP addresses, device types, and geolocation data, transmitting the stolen information to a private Telegram channel controlled by the attackers. To avoid suspicion, the fake login page displays an error message, making victims believe they simply mistyped their password.
Forcepoint has since updated its defenses to detect and block these files, but the campaign highlights how attackers are increasingly abusing trusted formats and cloud infrastructure to bypass security measures. The incident underscores the risks of assuming routine business documents are safe without verifying their origin.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
734
DECEMBER 2025
732
NOVEMBER 2025
732
NOVEMBER 2024
735
Cyber Attack
01 Nov 2024 • Dropbox
Facebook, Dropbox and MediaFire: Threat Actors Exploit Copyright Takedowns to Deliver Malware
Lone None Threat Group Deploys New Stealers via Fake Copyright Takedown Notices
717
CRITICAL-18
FACDROMED1768636787
Lone None Threat Group Deploys New Stealers via Fake Copyright Takedown Notices
Since November 2024, the Lone None threat actor group has been orchestrating a sophisticated email campaign distributing two information stealers: Pure Logs Stealer and the newly identified Lone None Stealer (PXA Stealer). The campaign spoofs legal firms worldwide, using copyright infringement takedown notices as lures to trick recipients into executing malicious payloads.
The emails, written in at least ten languages likely via machine translation or AI reference authentic Facebook accounts of victims to enhance credibility. Embedded links, often shortened via t[.]ee or g[.]su, redirect to free file-hosting services like Dropbox and MediaFire, where victims download an archive disguised as a PDF reader installer.
In reality, the archive contains a repurposed Haihaisoft PDF Reader executable, a malicious DLL acting as a Python installer, legitimate documents, and files with mismatched extensions. Upon execution, the loader uses Windows certutil.exe to decode a disguised PDF archive, saving it under a different extension. A bundled WinRAR executable (renamed "images.png") extracts the decoded files into C:\Users\Public.
The malicious DLL then launches a staged Python interpreter (svchost.exe), installing Python in the same directory and executing an obfuscated script. The script communicates with a Telegram bot C2 channel, where part of a paste[.]rs URL is stored in the bot’s bio. The script reconstructs the URL to fetch a secondary payload from 0x0[.]st, delivering either Pure Logs Stealer or Lone None Stealer.
Both stealers employ Base64/Base85 encoding and AES encryption to evade detection. Lone None Stealer specifically targets cryptocurrency by monitoring the Windows clipboard for wallet addresses, replacing them with actor-controlled wallets for Bitcoin, Ethereum, and Solana. Observed wallet addresses include:
- Bitcoin: `1DPguuHEophw6rvPZZkjBA3d8Z9ntCqm1L`
- Ethereum: `0xd38c3fc36ee1d0f4c4ddaeebb72e5ce2d5e7646c`
- Solana: `GQwKEEi49iKywE8ycnFsxRhxJTVf6YsoJb2vAFigc8`
Earlier variants delivered XWorm and DuckTail, but recent attacks have streamlined to focus on Pure Logs Stealer’s RAT capabilities and Lone None Stealer’s cryptocurrency theft. Persistence is maintained via a registry Run key pointing to the staged Python interpreter.
Defenders are advised to monitor for clandestine Python installations in C:\Users\Public\Windows, suspicious Run key entries, and anomalous executions of certutil.exe and WinRAR with renamed files. The campaign underscores the evolving tactics of threat actors in leveraging social engineering and unconventional C2 channels to distribute malware.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2022
775
Breach
01 Nov 2022 • Dropbox
Dropbox
Dropbox Data Breach
710
CRITICAL-65
DRO121761222
Dropbox confirmed that it had experienced a data breach incident in November 2022.
After an unknown attacker gained access to credentials, data, and other secrets within their private GitHub code repositories.
Dropbox did admit that the code contained a "few thousand names and email addresses belonging to Dropbox staff," as well as some plain text secrets like API keys and other credentials.
They adopt common security precautions like frequent password changes and turning on MFA for your storage account.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Dropbox ??
What was Dropbox's A.I Rankiteo Cyber Score in September 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in August 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in July 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in June 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in May 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in April 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in March 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in February 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in January 2026 ??
What was Dropbox's A.I Rankiteo Cyber Score in December 2025 ??
What was Dropbox's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Dropbox's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Dropbox ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Dropbox's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?