View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
October 20, 2014

Dropbox shuts down phishing scam

Symantec warns that users may not understand SSL security.

By Jimmy Nicholls

Dropbox has shut down a phishing scam aimed at stealing the credentials of its users, according to the security firm Symantec.

Users were sent messages linking to a phoney login page hosted on the official Dropbox site, with scammers claiming they were trying to transfer a document that was either too big or too sensitive to be sent through email.

Nick Johnston, a Symantec staffer, said: "The page looks like the real Dropbox login page, but with one crucial difference.

"The scammers are interested in phishing for more than just Dropbox credentials; they have also included logos of popular web-based email services, suggesting that users can log in using these credentials as well."

Once information was entered into a form it was said to be transferred to a compromised web server, with details being covered with an SSL security certificate in order to increase the attack’s plausibility, as modern browsers often warn against sending non-SSL resources on an SSL-enabled page.

"The prominence of the warning varies from browser to browser; some browsers simply change the padlock symbol shown in the address bar, whereas others include a small banner at the top of the page," Johnston added.

However he said that users might not understand the significance of SSL or respond to warnings messages when it was not being used.

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU