Dropbox Discloses Breach of Digital Signature Service Affecting All Users
ID: 9cac71fc-5566-5e73-8760-036d73cd5bcf
STIX ID: report--9cac71fc-5566-5e73-8760-036d73cd5bcf
Feed Name: The Hacker News
Dropbox disclosed an April 24, 2024 breach of its Dropbox Sign (formerly HelloSign) service in which attackers accessed user emails, usernames and general account settings for all Sign users, and for subsets additionally obtained phone numbers, hashed passwords, API keys, OAuth tokens, and some authentication information; names and email addresses of third-party document recipients/signers were also exposed. Dropbox reports no evidence that document contents or payment information were accessed, attributes the intrusion to a compromised service account and an automated configuration tool, has reset credentials and is rotating keys, and is notifying affected users while coordinating with law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
