← Blog
Industry security11 min read

Creative and advertising agencies: client briefs, Google Workspace takeovers and ransomware

Fancy Films, Google Ads account takeovers, Teams vishing: how agencies leak client campaigns and assets — and how zero-knowledge storage keeps a compromised account worthless.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

An agency holds other people's secrets Unreleased campaigns, embargoed product shots, client strategy decks, talent contracts, budgets, NDAs. Almost none of it belongs to the agency, and almost all of it lives in Slack, Google Drive, Teams or Dropbox — plaintext, indexed, and one credential away.

What actually happens to agencies

Fancy Films (Australia, 2025) — claimed by KillSec An extortion group claimed client files, insurance policies and inventories of video and editing equipment. A creative shop is a rich, soft target: valuable client material, small security budget.

Google Workspace and Google Ads account takeovers The most common agency incident is not exotic. A phished or session-hijacked Workspace account gives an attacker the agency's **Google Ads** access: fraudulent campaigns run on the agency card, invoices explode, and the same identity often reaches shared client Drive folders in the process. Recovery is slow because the ad platform sees a legitimate, authenticated user.

Microsoft Teams vishing → ransomware A now-standard playbook: an attacker messages or calls staff **through Teams**, posing as internal IT support, and talks them into granting remote access. Because the message arrives inside the trusted internal tool, it defeats normal email-phishing instincts.

Supply-chain and freelance sprawl Agencies work with freelancers, retouchers, production partners and clients simultaneously. Shared folders accumulate members nobody removes. One compromised freelance laptop is a live path into the shared drive.

Malicious-ad and infostealer campaigns Infostealer malware — the same class that took Nikkei's Slack credentials — harvests browser cookies wholesale. Session cookies bypass MFA entirely, which is exactly how the EA Slack intrusion started.

Why this cannot play out the same way on DRIVUNO DRIVUNO encrypts files, messages and shared team folders **on your device** before transmission. Keys come from your credentials and never exist in readable form on our side.

  • A stolen session gives ciphertext. A hijacked cookie does not open a client's campaign, because opening it requires keys that were never uploaded.
  • No provider-side readability. No employee, no support tool, no legal order can produce a readable asset. There is no readable copy on our infrastructure.
  • Compromise stays contained. Access is granted per person and per folder, not per workspace. A compromised freelance account reaches only what it was individually sealed into, and removing them rotates the keys.
  • External sharing expires. Public links live at most 24 hours, and what is needed to open them never reaches our servers — no permanent "review link" circulating forever.
  • Bulk download is detected and slowed. Every account has an adaptive ceiling calibrated on its own normal traffic, so heavy asset delivery works while a full-archive sweep triggers an alert and automatic throttling.
  • Ransomware does not erase history. Continuous encrypted mirroring keeps versions, and our own backups are immutable for a fixed retention window.
  • No third-party analytics or marketing tags. One less vendor able to be breached on your clients' behalf.

We do not publish thresholds, heuristics or internal response procedures.

Practical takeaways for an agency 1. Separate the advertising-platform identity from the file-storage identity. 2. Audit shared folders quarterly and remove everyone who finished a project. 3. Treat internal chat as an untrusted channel for "IT support" requests. Verify out of band. 4. Store client material where the provider cannot technically read it — it is also the cleanest answer in an NDA negotiation.

Encrypted storage that survives a compromised account DRIVUNO gives agencies encrypted storage, per-client encrypted team folders, encrypted internal messaging and continuous encrypted backup of local working directories.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

End-to-end encrypted