logo

Threat Actors Abuse Trust in Cloud Collaboration Platforms

ID: 89171c75-d16f-5172-9b3d-ce4a1ec978a3

STIX ID: report--89171c75-d16f-5172-9b3d-ce4a1ec978a3

Feed Name: Cofense Blog

Date Published: 2025-03-26

Date Updated: 2026-04-27

Author: Cofense

...
...

Threat actors increasingly exploited trusted cloud collaboration and document-hosting services to deliver credential phishing that bypasses secure email gateways throughout 2024; Dropbox (25.5%) led abuse, Adobe and SharePoint each around 17%, DocuSign ~16% (often with QR codes), Google Docs ~11%, Canva ~9%, and Zoho ~4% with a notable December spike. The report explains how platform features (automatic notification emails, link expiration, and general domain trust) complicate detection and takedowns, with varying provider responsiveness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.