Security Breach Exposes Dropbox Sign Users (2024)

Cloud storage giant Dropbox has disclosed a significant breach in its systems, exposing customers’data to unauthorized entities.

The incident, detailed in a new regulatory filing, primarily affected Dropbox Sign, a service akin to DocuSign, allowing users to manage documents online.

According to the document, management became aware of the breach on April 24 and promptly initiated cybersecurity measures.

The investigation revealed that the attackers accessed various user data, including emails, usernames, phone numbers, hashed passwords and authentication information like API keys and OAuth tokens.

“Authentication processes are put in place to prevent cyber criminals from accessing systems or accounts even when they have stolen credentials,”explained Stephen Robinson, senior threat intelligence analyst at WithSecure.

“However, the theft of authentication data such as tokens and certificates can allow these security processes to be completely bypassed.”

Additionally, as reported in a blog post published on Wednesday by Dropbox, even individuals who interacted with Dropbox Sign without creating an account had their information compromised.

The company said it found no evidence of access to the contents of users’accounts or payment information. It appears that the attack was contained within the Dropbox Sign infrastructure, sparing other Dropbox products. This isolation underscores the complex nature of Dropbox’s IT environment, stemming from its acquisition of HelloSign in 2019.

The breach reportedly stemmed from a compromised service account within Dropbox Sign’s backend, allowing the attackers to access the customer database. In response, Dropbox has taken measures such as resetting passwords, logging out users from connected devices, and rotating API keys and OAuth tokens.

“Incidents such as this show how critical it is for large organizations to improve cyber-resilience,”Robinson added. “Cost-effective methods we advise all organizations to implement include regular risk assessments, rigorous patching schedulesand fostering a strong cybersecurity culture supported by clear security policies.”

Read more on Dropbox news: Dropbox Used to Steal Credentials and Bypass MFA in Novel Phishing Campaign

Despite the breach, Dropbox reassured investors that it hasn’t had a significant financial impact. Moving forward, the company plans to reach out to affected users with instructions on securing their data. The investigation is ongoing, with Dropbox promising further updates as they emerge.

Neither the regulatory filing nor the blog post mention provision offree identity protection services to affected users,commonly offered after data breaches.

Imagecredit: Dean Drobot / Shutterstock.com

Security Breach Exposes Dropbox Sign Users (2024)
Top Articles
9 Ways to Fix
How Credit Card Minimum Payments Are Calculated
Mickey Moniak Walk Up Song
How To Start a Consignment Shop in 12 Steps (2024) - Shopify
Menards Thermal Fuse
Methstreams Boxing Stream
Urist Mcenforcer
Restaurer Triple Vitrage
No Limit Telegram Channel
80 For Brady Showtimes Near Marcus Point Cinema
Soap2Day Autoplay
Craigslist Furniture Bedroom Set
5 Bijwerkingen van zwemmen in een zwembad met te veel chloor - Bereik uw gezondheidsdoelen met praktische hulpmiddelen voor eten en fitness, deskundige bronnen en een betrokken gemeenschap.
O'reilly's In Monroe Georgia
Calamity Hallowed Ore
CA Kapil 🇦🇪 Talreja Dubai on LinkedIn: #businessethics #audit #pwc #evergrande #talrejaandtalreja #businesssetup…
Paketshops | PAKET.net
Lantana Blocc Compton Crips
Cranberry sauce, canned, sweetened, 1 slice (1/2" thick, approx 8 slices per can) - Health Encyclopedia
The Rise of Breckie Hill: How She Became a Social Media Star | Entertainment
Brutál jó vegán torta! – Kókusz-málna-csoki trió
272482061
House Of Budz Michigan
Locate At&T Store Near Me
Yakimacraigslist
Pretend Newlyweds Nikubou Maranoshin
Missouri Highway Patrol Crash
Rugged Gentleman Barber Shop Martinsburg Wv
Www.publicsurplus.com Motor Pool
[Cheryll Glotfelty, Harold Fromm] The Ecocriticism(z-lib.org)
Dover Nh Power Outage
Lisas Stamp Studio
Grays Anatomy Wiki
Gabrielle Enright Weight Loss
Craigslist Albany Ny Garage Sales
Roto-Rooter Plumbing and Drain Service hiring General Manager in Cincinnati Metropolitan Area | LinkedIn
Tal 3L Zeus Replacement Lid
Frank 26 Forum
Final Fantasy 7 Remake Nexus
The best bagels in NYC, according to a New Yorker
Setx Sports
Todd Gutner Salary
Martha's Vineyard – Travel guide at Wikivoyage
Autozone Battery Hold Down
Oklahoma City Farm & Garden Craigslist
Movie Hax
Minterns German Shepherds
Wzzm Weather Forecast
Bismarck Mandan Mugshots
sin city jili
Hy-Vee, Inc. hiring Market Grille Express Assistant Department Manager in New Hope, MN | LinkedIn
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 5607

Rating: 4.3 / 5 (64 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.