<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Financial-Sector on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/financial-sector/</link><description>Recent content in Financial-Sector on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 09:33:57 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/financial-sector/index.xml" rel="self" type="application/rss+xml"/><item><title>Executive Outlook Mailbox Spied on via OneDrive &amp; Dropbox</title><link>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox/</link><pubDate>Thu, 04 Jun 2026 09:33:57 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox/</guid><description>Attackers silently exfiltrated a stock exchange executive&amp;#39;s Outlook email for five months, hiding data theft behind Dropbox and OneDrive traffic.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">The Hacker News</a></p>
<hr>
<p>Unknown threat actors maintained covert access to a senior stock exchange executive&rsquo;s Outlook mailbox for at least five months, quietly exfiltrating email data in small batches to evade detection. The stolen data was routed through legitimate cloud storage services — Dropbox and OneDrive — to blend with normal business traffic. Symantec and Carbon Black attribute the campaign to espionage, suggesting a nation-state or sophisticated threat actor targeting financial sector intelligence.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review Microsoft 365 audit logs and Conditional Access policies for unusual mailbox delegation, mail forwarding rules, or OAuth app consents — particularly any third-party app with access to Mail.Read scopes. Implement Cloud App Security (Defender for Cloud Apps) policies to alert on bulk email access or large data transfers to consumer cloud storage services such as Dropbox and OneDrive.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">Hackers Spied on a Stock Exchange Executive&rsquo;s Outlook Mailbox for Five Months</a></p>
]]></content:encoded></item></channel></rss>