logo

Dropbox Sign customer data accessed in breach

ID: a40e22c8-674a-53e7-a862-6c7190196bde

STIX ID: report--a40e22c8-674a-53e7-a862-6c7190196bde

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-05-02

Date Updated: 2026-04-28

...
...

Dropbox Sign suffered an incident where an attacker compromised a back-end service account and accessed customer data (emails, names, usernames, phone numbers, hashed passwords) and sensitive authentication material (API keys, OAuth tokens, MFA information). Dropbox says the breach was limited to the Sign environment, has reset passwords, logged users out, and is rotating API keys and tokens while notifying regulators and law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.