Description

Dropbox, the cloud storage company, disclosed a recent cybersecurity breach where a hacker accessed sensitive information, including passwords, following unauthorized access to the production environment of Dropbox Sign (formerly HelloSign), an entity acquired in 2019. The breach impacted all users of Dropbox Sign, exposing account settings, names, emails, and in some cases, phone numbers, hashed passwords, and authentication data like API keys and OAuth tokens. However, Dropbox stated that there's no evidence the hacker accessed the contents of users' accounts or payment information. Forensic investigators have been engaged, law enforcement notified, and regulatory agencies are being informed, anticipating potential access to personal data. While Dropbox believes the breach won't significantly impact its operations or financial status, it anticipates potential repercussions like litigation, changes in customer behavior, and heightened regulatory scrutiny. As part of their response, Dropbox is notifying affected users and advising on specific actions. For customers with API access, new API keys are required, with temporary restrictions until keys are rotated. Despite this breach, Dropbox remains operational, with business continuity ensured for signature requests and signing capabilities, pending API key updates for unrestricted functionality.