Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A February 2026 phishing report describes a procurement email that used an attached PDF, a second PDF hosted on Vercel, and a fake Dropbox sign-in page to steal credentials. The report concerns one observed campaign—not evidence that Dropbox, Vercel, or PDFs are inherently unsafe. The practical warning is to check the entire route behind an unexpected login request, not just the file type or familiar branding.

How the reported phishing chain worked

Forcepoint X-Labs described the campaign on February 2, 2026. It began with a business-style procurement or tender request and moved through two PDFs before reaching a fraudulent login page.

  1. A procurement-themed email set the pretext. The message asked the recipient to review an attached request order and reportedly contained no malicious link in its body. Forcepoint said the sender address was likely spoofed or associated with a compromised account. The reported subject was e-Tender (Operating Unit - Standard P.O requires your acceptance).
  2. The attachment linked to another PDF. The first file, named 2026_PO_I0I_Jan_25_LGXZ.pdf, included a clickable “View specification online Here:” element. Forcepoint’s analysis identified FlateDecode-compressed streams and AcroForm objects in the file. The link opened ProductLists.pdf on Vercel Blob infrastructure.
  3. The second PDF led to a lookalike sign-in page. That document served as a staging or redirect step to a newly registered fraudulent domain. The page impersonated Dropbox, but Forcepoint said the domain had no affiliation with Dropbox.
  4. The page collected credentials and tried to look convincing. According to Forcepoint, it captured the submitted email address and password, attempted to collect IP and geolocation details, and sent data through a Telegram bot API. After a five-second delay, it simulated a login attempt and displayed an invalid-credentials error.

An error message does not establish that nothing was submitted. In this reported chain, the credential collection occurred before the page displayed its simulated error.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the chain can be harder to spot than a suspicious link

The email did not need a conspicuous link in its body. Instead, each handoff looked plausible in isolation: a routine purchase request, a PDF specification, a document hosted on a recognizable cloud platform, and a login page bearing a familiar brand. The risk became clearer when the steps were considered together.

That distinction matters: Vercel Blob was hosting the linked PDF in the reported chain, but that does not make Vercel or its other hosted content malicious. Likewise, PDFs and Dropbox were parts of the lure, not proof that either is inherently unsafe. A recognizable logo or reputable hosting service cannot authenticate the final destination or explain why a sign-in is needed.

CSO Online quoted Erik Avakian, technical counselor at Info-Tech Research Group, describing the pattern: “Each step, by itself, passes the sniff test.” He added: “The danger only becomes obvious when you zoom out and look at the entire chain, and most users don’t think about chains. They think in clicks.”

What to do if a business PDF unexpectedly asks you to sign in

  • Verify the request out of band. For an unexpected purchase order, tender, invoice, or contract, contact the supposed sender using a phone number or contact route you already trust—not details supplied in the message. Forcepoint’s advice, quoted by CSO, was to confirm business documents with known vendors, affiliates, or agencies.
  • Pause at the login prompt. Check the actual domain in the browser and ask whether the document genuinely requires you to sign in. Do not rely on a Dropbox logo, a PDF extension, or the fact that an earlier file was hosted on a reputable service.
  • Report suspicious messages and attachments. Send them to your organization’s IT or security team using its established reporting process. Do not forward a suspected credential-harvesting link broadly. CSO reported Forcepoint researcher Lionel Menchaca’s advice to report suspicious email to IT or security when it cannot be verified.
  • If you entered a password, respond promptly. Use a trusted route—not the link in the message—to change it, review and revoke active sessions where available, and notify your organization’s security team. These are prudent response steps based on the reported credential-theft mechanism; the campaign report does not give a detailed recovery procedure.

How organizations can reduce the risk

The chain points to a defense-in-depth approach rather than a single file-type rule. Email and security teams can assess whether their controls:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Inspect PDF attachments and their embedded links.
  • Follow links through redirects and analyze the final destination, rather than treating a familiar hosting provider as sufficient proof of safety.
  • Make it easy for employees to report suspicious messages and route those reports into investigation and response.
  • Pair email and URL inspection with account protections. CSO quoted practitioner recommendations for multifactor authentication (MFA), conditional access, and anomaly detection. These measures can limit damage, but they are not guarantees that every attack will be blocked.

David Shipley of Beauceron Security told CSO: “This is a perfect example of why phishing is still the number one way for criminals to get at organizations.” He estimated that about 40% of email clicks happen when people are on autopilot; CSO’s report did not provide a study, sample, or methodology for that estimate, so it should not be read as a measured universal rate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the published indicators do—and do not—tell you

Forcepoint published campaign-specific indicators in its February 2, 2026 analysis, including the two filenames, their SHA-1 hashes, the Vercel Blob-hosted PDF, a redirect URL on tovz[.]life, and a Telegram Bot API endpoint. These are historical indicators tied to the reported sample, not proof of current activity. Domains and other infrastructure can be taken down, repurposed, or cease to be useful indicators; their current status is not established here. Do not visit the indicators to test them.

The report does not establish how many people were targeted or affected, who operated the campaign, whether its infrastructure remains active, or whether later campaigns reused it. It documents a particular credential-phishing chain and the methods observed in that sample.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.