US Dropbox 2012 Hacking (Q9130)

From Open Risk Manual
A data breach risk event
Language Label Description Also known as
English
US Dropbox 2012 Hacking
A data breach risk event

    Statements

    0 references
    0 references
    January 2012
    0 references
    A couple of weeks ago Dropbox hired some "outside experts" to investigate why a bunch of users were getting spam at e-mail addresses used only for Dropbox storage accounts. The results of the investigation are in, and it turns out a Dropbox employees account was hacked, allowing access to user e-mail addresses. In an explanatory blog post, Dropbox today said a stolen password was "used to access an employee Dropbox account containing a project document with user email addresses." Hackers apparently started spamming those addresses, although theres no indication that user passwords were revealed as well. Some Dropbox customer accounts were hacked too, but this was apparently an unrelated matter. "Our investigation found that usernames and passwords recently stolen from other websites were (English)