Dropbox in password reuse security breach
Same password used on multiple sites results in Dropbox account compromisation.


Dropbox has admitted that a number of customers have been spammed following a breach of its infrastructure that led to a number of accounts being compromised.
The cloud storage provider said that it was made aware of the breach when account holders reported receiving unwanted messages in email accounts used only for Dropbox communications.
The company said in a blog post that it had taken action to investigate claims.
"A couple weeks ago, we started getting emails from some users about spam they were receiving at email addresses used only for Dropbox. We've been working hard to get to the bottom of this, and want to give you an update," said Aditya Agarwal, vice president of Engineering at Dropbox.
"Our investigation found that usernames and passwords recently stolen from other websites were used to sign in to a small number of Dropbox accounts. We've contacted these users and have helped them protect their accounts."
The company confirmed that several other accounts were also compromised when an employee's Dropbox account also got hacked.
"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses," said the company.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We believe this improper access is what led to the spam."
Dropbox apologised for the breach and said it would now put additional controls in place to help make sure it doesn't happen again.
The company has now reset affected customers' passwords and will be implementing two-factor authentication including temporary codes sent to mobile phones when signing in.
It also plans to introduce automated mechanisms to help identify suspicious activity. Dropbox said it would also continue to add more of these over time.
Neil Cook, chief technology officer of security company Cloudmark said that the breach was "unsophisticated".
"The offending messages were hitting a handful of spammy fingerprints at once," he said. "If this were an exam, the spammer would receive an ungraded' mark for lack of message complexity or originality."
Cook added that recent data from Cloudmark's Global Threat Network found that there were 264 different domains in use by this spammer.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Meta just revived plans to train AI models using European user data
News Meta has confirmed plans to train AI models using European users’ public content and conversations with its Meta AI chatbot.
By Nicole Kobie
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
I love magic links – why aren’t more services using them?
Opinion Using magic links instead of passwords is safe and easy but they’re still infuriatingly underused by businesses
By Solomon Klappholz
-
Password management startup Passbolt secures $8 million to shake up credential security
News Password management startup Passbolt has secured $8 million in funding as part of a Series A investment round.
By Ross Kelly
-
LastPass breach comes back to haunt users as hackers steal $12 million in cryptocurrency
News The hackers behind the LastPass breach are on a rampage two years after their initial attack
By Solomon Klappholz
-
GitHub launches passkeys beta for passwordless authentication
News Users can now opt-in to using passkeys, replacing their password and 2FA method
By Daniel Todd
-
Microsoft SQL password-guessing attacks rising as hackers pivot from OneNote vectors
News Database admins are advised to enforce better controls as attacks ending in ransomware are being observed
By Rory Bathgate
-
No, Microsoft SharePoint isn’t cracking users’ passwords
News The discovery sparked concerns over potentially invasive antivirus scanning practices by Microsoft
By Ross Kelly
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly
-
Microsoft Authenticator mandates number matching to counter MFA fatigue attacks
News The added layer of complexity aims to keep social engineering at bay
By Connor Jones