Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • 5 Active Malware Campaigns in Early 2025: What You Need to Know
    • 10 Critical Network Pentest Findings IT Teams Overlook
    • Report Phishing Instantly with PhishAlarm
    • Password Reuse Epidemic: Nearly Half of User Logins Compromised
    • Women in Cybersecurity: Interest, Exposure, or Just Stereotypes??
    • Stay Ahead of Scammers in 2025
    • Cybersecurity Alert: Risks of Abandoned Websites
    • DHS Unveils Playbook for the Deployment of Artificial Intelligence for the Public Sector
    Fordham University Information Security and Assurance
    • Information Security and Assurance Homepage
    • Privacy Blog
    • About
    Fordham University Information Security and Assurance
    You are at:Home»Alerts»Article: Dropbox hack ‘affected 68 million users’
    Alerts

    Article: Dropbox hack ‘affected 68 million users’

    By Gerald Johnson Jr.September 1, 20163 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Copy Link

    _90982297_dropbox-for-android-3-0-1

     

    “A Dropbox security breach in 2012 has affected more than 68 million account holders, according to security experts.

    Last week, Dropbox reset all passwords that had remained unchanged since mid-2012 “as a preventive measure”.

    In 2012, Dropbox had said hacks on “other websites” had affected customers who used their Dropbox password on other sites too.

    But now what purports to be the details of 68.6 million Dropbox accounts have emerged on hacker trading sites.

    The 5GB document has been acquired by a Motherboard reporter, who also said it had been verified as genuine by a “senior Dropbox employee” speaking on the condition of anonymity.

    The data includes email addresses and hashed passwords.

    But security researcher Troy Hunt, who has also seen the document, said the hashing algorithm that obscured the passwords was “very resilient to cracking”.

    “Frankly, all but the worst possible password choices are going to remain secure even with the breach now out in the public,” he said.

    Mr Hunt said he had managed to independently verify the hack by finding the password of his wife within the cache.

    He told BBC News the document contained a “very unique, 20-character, completely random password” used by his wife to login to Dropbox.

    It had been created by a password manager, he said, making the chance of it having been correctly guessed “infinitely small”.

    Mr Hunt wrote his blog: “There is no doubt whatsoever that the data breach contains legitimate Dropbox passwords – you simply can’t fabricate this sort of thing.”

    Security researcher Ken Munro also said the hack appeared to be genuine and to have “taken place in 2012”.

    In a statement sent to the BBC, Dropbox said: “This is not a new security incident.”

    And there was “no indication” Dropbox user accounts had been improperly accessed.

    “Our analysis confirms that the credentials are user email addresses with hashed and salted passwords that were obtained prior to mid-2012,” said the statement.

    “We can confirm that the scope of the password reset we completed last week did protect all impacted users.

    “Even if these passwords are cracked, the password reset means they can’t be used to access Dropbox accounts.”

    Meanwhile, on Tuesday the password management service OneLogin – of which Dropbox is a client – revealed that a user gained access to one of its systems used for log storage and analytics.

    Alvaro Hoyos, chief information security officer at OneLogin, has said that this incident is not connected to the Dropbox hack.

    “We have no indication that OneLogin’s August 2016 incident is connected to any further incidents currently in the news,” Mr Hoyos told the BBC.

    “To reiterate what our recent blog post stated, the impacted system is a standalone system and there are no signs of suspicious activity in any of our other systems.

    “The security of our customers is of the utmost importance and we are carrying out an extensive investigation in partnership with a third-party cybersecurity firm. We are advising impacted customers as soon as any additional information becomes available as a result of the investigation.””

    Source: http://www.bbc.com/news/technology-37232635

    Share this:

    • Click to share on X (Opens in new window) X
    • Click to share on Facebook (Opens in new window) Facebook
    • Click to share on LinkedIn (Opens in new window) LinkedIn

    Like this:

    Like Loading...
    Previous ArticleFYI – Phishing Email Sent to the Fordham Community on 08/29/2016
    Next Article Article: Update OS X Right Now or You Could Get Some Nasty Spyware

    Related Posts

    10 Critical Network Pentest Findings IT Teams Overlook

    Cybersecurity Alert: Risks of Abandoned Websites

    What You Need to Know About Emerging Data Privacy Trends in 2025

    Follow Us on Twitter!
    Follow @FordhamSecureIT
    My Tweets
    Archives
    Categories
    • AI (1)
    • Alerts (384)
    • CISO (19)
    • Cyber Security Awareness Month Tip (150)
    • Data Privacy Week (2)
    • Executive Director (1)
    • Exploits and Vulnerabilities (35)
    • General Information (34)
    • Identity and Access Management (12)
    • Identity Theft (26)
    • Jason Benedict (19)
    • Legitimate Email (14)
    • Malicious Email (24)
    • Mobile (25)
    • Network Security (2)
    • News and Events (143)
    • Newsletter (13)
    • Password (17)
    • Phishing (333)
    • Phishing Email (340)
    • Privacy (10)
    • Ransomware (9)
    • Scam (104)
    • Security Awareness (262)
    • Security Guides (34)
    • Social Engineering (12)
    • SPAM (40)
    • Suspicious (6)
    • Telework (2)
    • Teleworking (3)
    • Trojan (7)
    • Uncategorized (9)
    • Virtual Meeting (4)
    • Virus (28)
    • Viruses (8)
    • World Backup Day (1)
    • Zoom (6)
    Tag Cloud
    Alerts Artificial Intelligence Backups cell phones CISO Cybersecurity Awareness Month Tip Cybersecurity Month Data Privacy Device email Exploits and Vulnerabilities fordham fraud Identity and Access Management Identity Theft Information Security Guides Jason Benedict Legitimate Email malicious email Mobile Multi-Factor Authentication networks Network Security News and Events Newsletter online safety Online Shopping Password Phishing Phishing Email Privacy ransomware scam scams Security Awareness social engineering Social Media spam trojan Virus Viruses Wireless wire transfer scam World Backup Day zoom
    About
    About

    Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.

    Copyright © Fordham University
    Facebook X (Twitter) Instagram YouTube LinkedIn
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    %d