Dropbox dropped the ball on security, haemorrhaging customer and third-party info
ID: 36b79643-159c-5298-8204-96fd0bb715f4
STIX ID: report--36b79643-159c-5298-8204-96fd0bb715f4
Feed Name: The Register (Security)
Dropbox disclosed a breach of its Dropbox Sign eSignature service after an attacker gained access to an automated system configuration service account on April 24; the actor accessed user emails, usernames, account settings and, for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and some authentication/MFA information. Dropbox says there is no evidence the attacker accessed document contents or payment information and that other Dropbox products appear unaffected; remediation actions include password resets, user logouts, and rotation of API keys and tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
