DropBox says hackers stole customer data, auth secrets from eSignature service
ID: d75a3afc-1295-52a7-ad46-959ea6a14989
STIX ID: report--d75a3afc-1295-52a7-ad46-959ea6a14989
Feed Name: Bleeping Computer
Dropbox Sign (formerly HelloSign) detected unauthorized access on April 24 to an automated configuration tool in its production environment that allowed attackers to execute services with elevated privileges and access the customer database. Exposed data included customer contact details, hashed passwords, API keys, OAuth tokens, and MFA keys; Dropbox has reset passwords, logged out sessions, restricted API key use pending rotation, and is notifying affected customers. There is no evidence that documents or other Dropbox services were accessed, but the company warns of potential phishing and urges users to rotate credentials and reconfigure MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
