Security Breach Exposes Dropbox Sign Users (2024)

Cloud storage giant Dropbox has disclosed a significant breach in its systems, exposing customers’data to unauthorized entities.

The incident, detailed in a new regulatory filing, primarily affected Dropbox Sign, a service akin to DocuSign, allowing users to manage documents online.

According to the document, management became aware of the breach on April 24 and promptly initiated cybersecurity measures.

The investigation revealed that the attackers accessed various user data, including emails, usernames, phone numbers, hashed passwords and authentication information like API keys and OAuth tokens.

“Authentication processes are put in place to prevent cyber criminals from accessing systems or accounts even when they have stolen credentials,”explained Stephen Robinson, senior threat intelligence analyst at WithSecure.

“However, the theft of authentication data such as tokens and certificates can allow these security processes to be completely bypassed.”

Additionally, as reported in a blog post published on Wednesday by Dropbox, even individuals who interacted with Dropbox Sign without creating an account had their information compromised.

The company said it found no evidence of access to the contents of users’accounts or payment information. It appears that the attack was contained within the Dropbox Sign infrastructure, sparing other Dropbox products. This isolation underscores the complex nature of Dropbox’s IT environment, stemming from its acquisition of HelloSign in 2019.

The breach reportedly stemmed from a compromised service account within Dropbox Sign’s backend, allowing the attackers to access the customer database. In response, Dropbox has taken measures such as resetting passwords, logging out users from connected devices, and rotating API keys and OAuth tokens.

“Incidents such as this show how critical it is for large organizations to improve cyber-resilience,”Robinson added. “Cost-effective methods we advise all organizations to implement include regular risk assessments, rigorous patching schedulesand fostering a strong cybersecurity culture supported by clear security policies.”

Read more on Dropbox news: Dropbox Used to Steal Credentials and Bypass MFA in Novel Phishing Campaign

Despite the breach, Dropbox reassured investors that it hasn’t had a significant financial impact. Moving forward, the company plans to reach out to affected users with instructions on securing their data. The investigation is ongoing, with Dropbox promising further updates as they emerge.

Neither the regulatory filing nor the blog post mention provision offree identity protection services to affected users,commonly offered after data breaches.

Imagecredit: Dean Drobot / Shutterstock.com

Security Breach Exposes Dropbox Sign Users (2024)
Top Articles
5 Things Not To Say To Someone Who Is Struggling With Money
1776-1976 50c US Kennedy Half Dollar, NGC MS65 Mint Error (80% off cen
Mackenzie Rosman Leaked
Jonathon Kinchen Net Worth
Insidious 5 Showtimes Near Cinemark Tinseltown 290 And Xd
Mail Healthcare Uiowa
Anki Fsrs
Lesson 2 Homework 4.1
Erin Kate Dolan Twitter
Sams Gas Price Fairview Heights Il
Shariraye Update
C-Date im Test 2023 – Kosten, Erfahrungen & Funktionsweise
Skylar Vox Bra Size
Bestellung Ahrefs
Moparts Com Forum
Interactive Maps: States where guns are sold online most
Houses and Apartments For Rent in Maastricht
Paychex Pricing And Fees (2024 Guide)
Wausau Obits Legacy
Rugged Gentleman Barber Shop Martinsburg Wv
Melissababy
Self-Service ATMs: Accessibility, Limits, & Features
Craigslist Personals Jonesboro
How to Download and Play Ultra Panda on PC ?
Purdue 247 Football
C&T Wok Menu - Morrisville, NC Restaurant
Ficoforum
800-695-2780
Marilyn Seipt Obituary
Medline Industries, LP hiring Warehouse Operator - Salt Lake City in Salt Lake City, UT | LinkedIn
Bfsfcu Truecar
Dell 22 FHD-Computermonitor – E2222H | Dell Deutschland
Obituaries, 2001 | El Paso County, TXGenWeb
lol Did he score on me ?
24 slang words teens and Gen Zers are using in 2020, and what they really mean
Goodwill Thrift Store & Donation Center Marietta Photos
John F Slater Funeral Home Brentwood
Craigslist Pets Huntsville Alabama
Conan Exiles Armor Flexibility Kit
Sand Castle Parents Guide
Stranahan Theater Dress Code
Blue Beetle Showtimes Near Regal Evergreen Parkway & Rpx
The Complete Uber Eats Delivery Driver Guide:
El Patron Menu Bardstown Ky
Washington Craigslist Housing
Is Chanel West Coast Pregnant Due Date
Sml Wikia
Epower Raley's
Phumikhmer 2022
Taterz Salad
When Is The First Cold Front In Florida 2022
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 5607

Rating: 4.3 / 5 (64 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.