The Fake IT Call and the Click That Opens the Door
Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

Key points
- Attackers are increasingly relying on social tricks: fake IT calls, cloned login pages and OAuth consent prompts that look routine.
- One recent wave hit around 5,000 Dropbox accounts through recycled credentials and abandoned session links.
- Phishing kits aimed at chief executives are being sold ready-made, complete with fake Microsoft and Google sign-in screens.
- A single mistyped letter in a web address can send users to a malicious clone of a real service.
- Old, forgotten app permissions on personal accounts are being used as a quiet way back in.
The hackers are not really hacking anymore. They are knocking.
A staffer gets a phone call from someone claiming to be from the IT helpdesk. A colleague shares a document that looks fine. An app the user vaguely remembers installing asks, politely, to reconnect. Click Allow, and the intruder is inside. No exploit code, no zero-day, meaning a software flaw the maker did not know about. Just a person being helpful.
That pattern runs through a new roundup from The Hacker News covering more than twenty recent incidents, and it is worth unpacking for anyone who uses a work email.
How are the attackers getting in without "hacking"?
They are using the tools and habits people already trust. Real cloud apps, real login screens, real-looking emails. The trick is convincing the user to hand over access voluntarily.
One common route is phishing, where criminals send fake messages to trick people into typing their password into a copycat website. The newer twist is that entire phishing kits, pre-built websites that mimic Microsoft 365 or Google Workspace sign-in pages, are being sold on criminal forums and tuned specifically for chief executives and finance staff. Buy the kit, point it at a target list, wait for logins.
Another route is OAuth abuse. OAuth is the system behind those "Sign in with Google" or "Allow this app to access your calendar" prompts. Attackers register an app with an innocent name, email a link, and ask the victim to approve it. Once approved, the app can read mail or files without ever needing the password again. Changing the password does not kick it out.
What happened with the Dropbox accounts?
Roughly 5,000 Dropbox accounts were taken over in a recent wave, largely through credential stuffing: attackers took username and password pairs leaked from unrelated breaches and tried them on Dropbox, betting that people reuse passwords. They were right often enough to matter.
Some of the takeovers also relied on stale session links, the little tokens that keep you logged in on old devices you forgot about. If those never expire, they are a quiet back door.
What about typosquatting and fake software guides?
Typosquatting is when a criminal registers a web address that is one letter off a real one. A user searching for a software download follows a top-ranking guide, clicks what looks like the official link, and installs a tampered version instead. The guide itself, sometimes on a blog or a Q&A site, was planted for exactly this purpose.
| Tactic | What it looks like | What it costs the victim |
|---|---|---|
| CEO phishing kit | Fake Microsoft or Google login page | Email and file access |
| OAuth consent trap | "Allow this app" prompt from an unknown app | Ongoing mailbox access |
| Credential stuffing | Silent Dropbox login from a new location | Files stolen or encrypted |
| Typosquatted download | Software guide linking to a look-alike site | Malware on the device |
What should ordinary users actually do?
Slow down on two things: phone calls that ask you to click or install something, and any prompt asking an app for access to your email or files. If IT calls, hang up and call back on the number you already have. Review the apps connected to your Google, Microsoft or Dropbox account every few months and remove anything you do not recognise. Use a password manager so you are not reusing the same password across sites.
None of this is glamorous. That is the point. The attackers are betting you are busy.



