DROPBOX, INC.

Apr 2024 · Graded Verified · Technology and Software · Government record

Incident summary

DROPBOX, INC.Apr 2024
Not yet quantified
VVerified
Dropbox Sign's production environment was reached through a compromised service account, a non-human identity carrying broad standing privileges that nobody was watching, and from there the intruder reached the customer database. Every user's email and username left, and for a subset so did the API keys, OAuth tokens, and MFA material: at a signature company, the very proofs of identity walked out as loot. The actor was never named.
Technology and Software
SEC 8-K, Item 1.05
Initial attack type compromised credentials confirmed · Impact data theft confirmed

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index