Five-Month Outlook Intrusion at Global Stock Exchange Exfiltrated via Dropbox, OneDrive

Threat hunters say the executive's mailbox was siphoned in small batches over consumer cloud channels — a pattern consistent with state-aligned espionage rather than financially motivated crime.

ThreatVectr Newsdesk· 3 min read
Five-Month Outlook Intrusion at Global Stock Exchange Exfiltrated via Dropbox, OneDrive
Share

Attackers sat inside the Outlook mailbox of a senior executive at a major global stock exchange for at least five months, quietly copying messages out through Dropbox and OneDrive to avoid tripping egress alarms.

The intrusion was disclosed this week by the Symantec and Carbon Black Threat Hunter Team, the joint research unit operating under Broadcom. The team did not name the exchange or the executive.

The operators worked patiently. Instead of bulk-dumping the mailbox, they staged repeated small transfers and pushed them to mainstream cloud storage services that the victim's environment already trusted. That choice matters. Traffic to Dropbox and OneDrive rarely stands out on a corporate network, and outbound volume to either provider is usually well within baseline.

Five months is a long dwell time even by espionage standards. It suggests the intruders had stable access, working credentials or token persistence, and a clear interest in what the executive was reading day to day rather than what could be monetised quickly.

The targeting profile is the tell. A single senior mailbox at a financial market operator, slow exfiltration, no observed extortion, no ransomware payload. That is not a cybercrime crew. The hunters characterised the activity as espionage-aligned, though no specific nation-state cluster has been attributed publicly.

What would be in such a mailbox? Listings pipeline correspondence. Regulator contacts. Board-level discussions about market structure, surveillance referrals, or pending enforcement matters. Pre-disclosure material on issuers. Any of it is valuable to a foreign intelligence service or to a well-resourced trading operation.

Neither the exchange nor its parent has been named, and there is no public indication of a regulatory filing tied to the intrusion. It is also unclear whether the attackers were evicted or whether the access was burned only when researchers surfaced the activity.

The abuse pattern is not new but is worth restating for defenders. Adversaries increasingly route exfil through sanctioned SaaS — Dropbox, OneDrive, Google Drive, Notion, GitHub — because blocking those services outright is operationally painful and DLP rules tuned to file types miss slow, chunked uploads of mail items.

A few things defenders can do now without waiting for IOCs:

  • Alert on personal or unmanaged Dropbox and OneDrive tenants being reached from corporate endpoints, not just on the domains themselves.
  • Treat executive mailboxes as crown-jewel assets with their own conditional access, session lifetime caps, and mailbox audit logging at the highest verbosity.
  • Hunt for MailItemsAccessed and Send events from sessions whose IP, ASN, or device ID drifts from the user's baseline, even when MFA is satisfied.
  • Review OAuth grants on executive accounts quarterly. Tokens outlive password resets.

The research team has not published indicators tied to a named actor. Expect follow-on reporting once the victim and the cluster are firmly linked.

© 2026 Threat Vectr