Proton Drive Phishing Turns Trusted Links into Ransomware

A trusted cloud link and a password in the same email make the payload look like a secure file handoff, which is exactly why this campaign can slip past the normal attachment mindset. The fake Interpol message pushes the user to open a password-protected Proton Drive file, then hands off a disguised executable for the last step. Bitdefender says the phishing campaign is targeting small businesses across Europe, Asia, the Middle East, and North America, with cases seen in food and agriculture, legal services, pharmaceuticals, media, technology, and finance. The lure claims to come from Interpol’s “Cybercrime Investigation Unit” and tries to force an urgent response around supposed suspicious activity. The broader risk is that reputation checks alone do not cover a malicious download delivered through a real hosted service. Any email stack that treats cloud storage and password-protected links as safer than attachments inherits the same blind spot.

Part of the PlainSec briefing for 2026-07-03

Sources