Larry found this one. The bad actor put a file on DropBox then seems to have waited or forced DropBox to send a ‘reminder’ that there was a file waiting for Larry. The email came from no-reply@dropbox.com because it was a prompt.
In the body of the reminder, it said ‘In case you missed it,’ followed by our client’s name, BUT the email address was not his regular email. That small difference would have been easy to miss.
It was the ’in case you missed it’ comment that caused Larry to look a little deeper. Please share this with your teams as a reminder to be diligent when deciding whether to open an attachment or click on a link. ALWAYS err on the side of caution, and if you’re not sure, pick up the phone! –CMW