Join our Partner Program | Fuel growth, scale impact, and eliminate cyber-driven payment fraud—together. Register Today
Need to Meet Nacha’s 2026 Requirements? See How
The 5x Surge in Payment Fraud in H1 See the Report
Cyber-driven fraud is the #1 CEO priority, according to World Economic Forum. Read More
Going to Black Hat 2026? | Stop by Booth #5839. Let's Meet Up

Behind the Breach: The Phishing Risk in Collaborative Cloud Tools 

2 minutes Read

By Trustmi | Last updated on May 19, 2026

2025-05-19T20:12:17+00:00 2026-05-19T20:39:38+00:00

The Gist

In 2024, nearly 9% of credential phishing campaigns exploited trusted cloud collaboration platforms like Dropbox, Adobe, and DocuSign to steal sensitive information. To bypass Secure Email Gateways (SEGs), attackers are increasingly embedding phishing links within files hosted on legitimate services that employees use and trust every day.

The most commonly abused platforms include Adobe, Docusign, Dropbox, Canva, and Zoho. Chosen for their ubiquity across organizations of all sizes, these services provide an ideal cover for credential threats. 

The Latest

These cloud platforms are appealing to attackers for one reason: trust. Employees are far less likely to question a Dropbox or DocuSign link than a strange domain. With GenAI making phishing content more convincing and targeted, that trust is weaponized. 

While abuse of platforms like DocuSign isn’t new, attackers increasingly shift towards tools with broader reach and weaker security. Here’s where they’re focusing—and why: 

  • Dropbox (25.5%): High user volume means phishing files often stay online longer, giving attackers more time to succeed. 
  • Adobe (17%): Malicious PDFs are commonly used and can often slip past SEGs undetected. 
  • SharePoint (17%): Fake accounts are used to impersonate colleagues or partners, making phishing messages seem internal. 
  • DocuSign (16%): Commonly used in both HR and QR Code phishing, thanks to readily available phishing templates on cybercrime marketplaces.  

Trustmi’s Take

These phishing campaigns reveal a deeper truth: traditional security tools aren’t designed to catch legitimate-looking activity inside trusted platforms. Secure Email Gateways weren’t built to inspect links inside Dropbox folders or detect abnormalities in a legitimate-looking SharePoint document. 

That’s the problem. Today’s attackers aren’t just spoofing emails—they’re embedding themselves into real systems and workflows, where everything looks routine. The invoice looks right. The vendor name checks out. The link comes from a familiar tool, but the intent is malicious, and often invisible to siloed security controls. 

Preventing this kind of fraud requires more than smarter filters. It demands behavioral context across the entire system: vendors, employees, payments, and platforms. That’s where the next evolution of fraud defense begins. 

Interested in how Trustmi can protect your organization’s finances? Book a demo with us today! 

$240 Billion Secured

Protecting businesses globally against socially engineered fraud and errors.

Up to 2.5% of Budget Saved

By Eliminating Fraud and Payment Errors

From Hours to Seconds

Manual Process Time Reduced

$240 Billion Secured

Protecting businesses globally against socially engineered fraud and errors.

Up to 2.5% of Budget Saved

By Eliminating Fraud and Payment Errors

From Hours to Seconds

Manual Process Time Reduced

Eliminate B2B Payment Fraud Today
See It In Action
To top
Trust Center Form

Get Access to Trustmi's Trust Center

Please enter your details


Trust Center Login

Login to access Trustmi's Trust Center