Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Dropbox DocSend

Dropbox DocSend Vendor Cyber Rating & Cyber Score

docsend.com

Share business-critical documents with confidence. Secure viewing plus game-changing analytics. ⚡️ www.docsend.com


Dropbox DocSend A.I CyberSecurity Scoring

Dropbox DocSend
Company Information
Website:http://www.docsend.com
Employees number:13
Number of followers:6,316
NAICS:5112
Industry Type:Software Development
Homepage:docsend.com
Dropbox DocSend Risk Score (AI oriented)
Between 700 and 749
logo
Dropbox DocSendSoftware Development
Updated:
29/06/2026
733/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Dropbox DocSend Global Score (TPRM)
xxxx
logo
Dropbox DocSendSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Dropbox DocSend
Dropbox DocSendModerate
Current Score
733Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
734Before Incident
JULY 2026
733Before Incident
JUNE 2026
733Before Incident
MAY 2026
733Before Incident
APRIL 2026
732Before Incident
MARCH 2026
750Before Incident
Cyber Attack
01 Mar 2026Dropbox DocSend
Dropbox and DocSend: The Hacker’s 2026 Playbook from the Dark Web

ConsentFix Phishing Campaign Exploiting OAuth Tokens in Microsoft 365 Accounts

731After Incident
LOW-19
DOCDRO1782743043
New Phishing Tactics Exploit OAuth Tokens in Microsoft 365 Accounts A sophisticated phishing campaign, dubbed ConsentFix, is targeting Microsoft 365 users by exploiting trusted platforms like Dropbox and DocSend to bypass security measures. Attackers send seemingly legitimate, password-protected lures that evade antivirus detection. Once opened, victims are tricked into dragging a localhost callback link into their browser or executing keyboard shortcuts (e.g., Windows key + R, Ctrl+V), unknowingly handing over OAuth tokens that grant full account access without requiring passwords or multi-factor authentication (MFA). The attack, first documented on a Russian cybercrime forum in early 2026, was shared as a step-by-step guide complete with code, infrastructure screenshots, and a video tutorial. This "playbook" lowers the barrier for entry, enabling even low-skilled threat actors to launch high-impact attacks. The campaign leverages free services like Cloudflare Pages and Pipedream webhooks to host malicious infrastructure, while LinkedIn and ZoomInfo data is used to tailor phishing lures to specific targets. Why It Works ConsentFix exploits routine user behavior, such as clicking through OAuth consent prompts or following familiar sign-in flows. Unlike traditional phishing, victims don’t enter credentials into fake forms instead, they complete what appears to be a legitimate authentication process, inadvertently surrendering session tokens. The attack is fast (under three seconds) and leaves minimal traces, though defenders can detect anomalies like suspicious PowerShell activity or unusual login locations. Impact Once compromised, attackers gain access to email, OneDrive, Teams, and other Microsoft 365 resources, enabling data theft, lateral movement, or further phishing campaigns. The technique has evolved from earlier variants like ClickFix, which relied on similar social engineering tactics but with even less technical friction. The campaign highlights a broader trend: cybercrime as a service (CaaS), where attack methods are packaged and distributed with step-by-step instructions, accelerating the spread of identity-based threats.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Data theft, lateral movement, further phishing campaigns
IMPACT
Data Compromised: Email, OneDrive, Teams, and other Microsoft 365 resourcesSystems Affected: Microsoft 365 accountsOperational Impact: Data theft, lateral movement, further phishing campaignsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: OAuth tokens, Microsoft 365 resources (email, OneDrive, Teams)Sensitivity Of Data: HighData Exfiltration: PossiblePersonally Identifiable Information: Possible
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Dropbox DocSend ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Dropbox DocSend's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Dropbox DocSend's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Dropbox DocSend ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Dropbox DocSend's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?