Security Breach Exposes Dropbox Sign Users (2024)

Cloud storage giant Dropbox has disclosed a significant breach in its systems, exposing customers’data to unauthorized entities.

The incident, detailed in a new regulatory filing, primarily affected Dropbox Sign, a service akin to DocuSign, allowing users to manage documents online.

According to the document, management became aware of the breach on April 24 and promptly initiated cybersecurity measures.

The investigation revealed that the attackers accessed various user data, including emails, usernames, phone numbers, hashed passwords and authentication information like API keys and OAuth tokens.

“Authentication processes are put in place to prevent cyber criminals from accessing systems or accounts even when they have stolen credentials,”explained Stephen Robinson, senior threat intelligence analyst at WithSecure.

“However, the theft of authentication data such as tokens and certificates can allow these security processes to be completely bypassed.”

Additionally, as reported in a blog post published on Wednesday by Dropbox, even individuals who interacted with Dropbox Sign without creating an account had their information compromised.

The company said it found no evidence of access to the contents of users’accounts or payment information. It appears that the attack was contained within the Dropbox Sign infrastructure, sparing other Dropbox products. This isolation underscores the complex nature of Dropbox’s IT environment, stemming from its acquisition of HelloSign in 2019.

The breach reportedly stemmed from a compromised service account within Dropbox Sign’s backend, allowing the attackers to access the customer database. In response, Dropbox has taken measures such as resetting passwords, logging out users from connected devices, and rotating API keys and OAuth tokens.

“Incidents such as this show how critical it is for large organizations to improve cyber-resilience,”Robinson added. “Cost-effective methods we advise all organizations to implement include regular risk assessments, rigorous patching schedulesand fostering a strong cybersecurity culture supported by clear security policies.”

Read more on Dropbox news: Dropbox Used to Steal Credentials and Bypass MFA in Novel Phishing Campaign

Despite the breach, Dropbox reassured investors that it hasn’t had a significant financial impact. Moving forward, the company plans to reach out to affected users with instructions on securing their data. The investigation is ongoing, with Dropbox promising further updates as they emerge.

Neither the regulatory filing nor the blog post mention provision offree identity protection services to affected users,commonly offered after data breaches.

Imagecredit: Dean Drobot / Shutterstock.com

Security Breach Exposes Dropbox Sign Users (2024)
Top Articles
MutualFunds.com
Cards
Camera instructions (NEW)
Celebrity Extra
Mopaga Game
Otterbrook Goldens
Red Wing Care Guide | Fat Buddha Store
سریال رویای شیرین جوانی قسمت 338
Palace Pizza Joplin
Derpixon Kemono
Zoebaby222
Spelunking The Den Wow
Bros Movie Wiki
Pro Groom Prices – The Pet Centre
Summoner Class Calamity Guide
RBT Exam: What to Expect
Samsung Galaxy S24 Ultra Negru dual-sim, 256 GB, 12 GB RAM - Telefon mobil la pret avantajos - Abonament - In rate | Digi Romania S.A.
Price Of Gas At Sam's
Moviesda3.Com
60 X 60 Christmas Tablecloths
Extra Virgin Coconut Oil Walmart
Nick Pulos Height, Age, Net Worth, Girlfriend, Stunt Actor
Ruben van Bommel: diepgang en doelgerichtheid als wapens, maar (nog) te weinig rendement
Bing Chilling Words Romanized
Energy Healing Conference Utah
Kcwi Tv Schedule
Great Clips Grandview Station Marion Reviews
Craigslist Apartments Baltimore
Munis Self Service Brockton
Walgreens Bunce Rd
Mta Bus Forums
Star Wars Armada Wikia
Grave Digger Wynncraft
In hunt for cartel hitmen, Texas Ranger's biggest obstacle may be the border itself (2024)
Log in or sign up to view
Basil Martusevich
Rund um die SIM-Karte | ALDI TALK
The Blackening Showtimes Near Regal Edwards Santa Maria & Rpx
Austin Automotive Buda
Hannibal Mo Craigslist Pets
Raisya Crow on LinkedIn: Breckie Hill Shower Video viral Cucumber Leaks VIDEO Click to watch full…
Academic important dates - University of Victoria
Craigslist Pets Huntsville Alabama
Orion Nebula: Facts about Earth’s nearest stellar nursery
Me Tv Quizzes
Best Restaurants Minocqua
Conan Exiles Armor Flexibility Kit
Secrets Exposed: How to Test for Mold Exposure in Your Blood!
Twizzlers Strawberry - 6 x 70 gram | bol
Billings City Landfill Hours
Kenmore Coldspot Model 106 Light Bulb Replacement
Noelleleyva Leaks
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 5607

Rating: 4.3 / 5 (64 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.