logo

Dropbox dropped the ball on security, haemorrhaging customer and third-party info

ID: 36b79643-159c-5298-8204-96fd0bb715f4

STIX ID: report--36b79643-159c-5298-8204-96fd0bb715f4

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-05-02

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Dropbox disclosed a breach of its Dropbox Sign eSignature service after an attacker gained access to an automated system configuration service account on April 24; the actor accessed user emails, usernames, account settings and, for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and some authentication/MFA information. Dropbox says there is no evidence the attacker accessed document contents or payment information and that other Dropbox products appear unaffected; remediation actions include password resets, user logouts, and rotation of API keys and tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.