
Dropbox has started notifying its users and asking them to change their account passwords, after a security breach that occurred in mid-2012.
The email message that users have received contains a link that points to a Dropbox help topic, where the company explains to its users the reasons for taking these steps. As Dropbox writes, the company recently became aware of the presence of some old user data on the internet. This data includes email addresses and hashed & salted passwords. After analyzing the data, the company believes that the breach occurred in mid-2012 and therefore asks all users who registered before mid-2012 to change their account passwords. The company links the incident to a blog post it wrote on July 31, 2012. Then Dropbox employees explained that some users who signed up on the site with a unique email address began receiving spam.
Dropbox investigated the issue and discovered that unknown hackers had access to some user accounts. Dropbox staff said that most incidents that occurred in 2012 were due to password reuse and not due to a server breach. Now, the company has decided to take this step before hackers start using old data. Dropbox's action is purely a precautionary measure. It's one of the fortunate cases where security really matters within the company.
