HomeSecurityHackers stole data from DropBox eSignature service

Hackers stole data from DropBox eSignature service

Cloud storage company DropBox says hackers breached the production systems of its DropBox Sign eSignature and gained access to authentication tokens, MFA keys, hashed passwords, and customer information.

See also: How to stop Dropbox from sending your files to OpenAI?

Dropbox eSignature

DropBox Sign (formerly HelloSign) is an eSignature platform that allows customers to send documents online to receive legally binding signatures.

The company says it detected unauthorized access to DropBox Sign production systems on April 24 and has launched an investigation. That investigation found that hackers gained access to an automated Dropbox Sign system configuration tool, which is part of the platform's support services.

This configuration tool allowed the malicious actor to run applications and automated services with elevated privileges, allowing the attacker to access the customer database.

"Upon further investigation, we discovered that a malicious actor had access to data, including Dropbox Sign customer information such as emails, usernames, phone numbers, and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication," Dropbox warns.

For users who used DropBox's eSignature platform but did not sign up for an account, their email addresses and names were also exposed. The company says it found no evidence that the hackers gained access to customer documents or agreements, and they did not have access to the platforms of other DropBox services.

See also: RansomHub group publishes Change Healthcare data

Hackers stole data from DropBox eSignature service

DropBox says it is resetting all users' passwords and advising them to log out of all DropBox eSignature sessions and restrict how they use API keys.

The company has provided additional information in the security advisory on how to switch API keys to regain full permissions.

Those using MFA with DropBox Sign will need to delete the configuration from their authentication apps and reconfigure it with a new MFA key retrieved from the website.

DropBox says it is currently emailing all customers affected by the incident. For now, DropBox eSignature customers should be on the lookout for potential phishing that use this data to collect sensitive information, such as plaintext passwords.

If you receive an email from DropBox eSignature asking you to reset your password, do not follow any links in the email. Instead, visit DropBox eSignature directly and reset your password from the website.

See also: Brazil: Has the data of millions of citizens been leaked?

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Technology tools can play a vital role in preventing data theft. One of the most effective ways is through the use of encryption, which converts data into a format that can only be decrypted with a special key. In addition, intrusion detection tools can identify suspicious activities or attacks on the network, allowing businesses to react quickly and prevent data theft. Access management tools can also help prevent data theft by controlling who has access to what data and when. This can prevent unauthorized access to sensitive information.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS