Doubloon Dredger Hijacks Notion Trust for Token Theft

Sublime’s Threat Intelligence & Research team says Doubloon Dredger used compromised Notion accounts and malicious PDFs in a July 2026 campaign to steal Microsoft authentication tokens from targeted organizations. The lure looked like a normal document-share notice from a coworker, but it came from legitimate Notion infrastructure, so it passed DKIM, SPF, and DMARC checks. The link chain pushed victims through a PDF to a fake Adobe-style page that showed a code and pointed them to Microsoft’s real device-code sign-in flow. If the victim entered that code, the attacker could collect an authorization token without ever seeing the password, which is why mail authentication alone did not stop the theft. That leaves organizations using Notion alerts and Microsoft device-code sign-in exposed to a trust break at the collaboration layer, not just the inbox. Sublime also tied 603 related scripts to EvilTokens and Tycoon2FA, suggesting a repeatable phishing supply chain rather than a single lure.

Part of the PlainSec briefing for 2026-08-24

Every edition of this story: Doubloon Dredger Hijacks Notion Trust for Token Theft

Sources