Dropbox Sign production systems breached, user credentials exposed
- Organization
- Dropbox
- Exploit
- Hacking
- Industry
- Technology
Dropbox disclosed on 1 May 2024, in a filing with the US Securities and Exchange Commission, that an attacker had reached the production environment of Dropbox Sign, its electronic signature service formerly known as HelloSign. The company said it discovered the unauthorised access on 24 April 2024.
Dropbox said a third party gained access to a Dropbox Sign automated system configuration tool and compromised a service account that was part of Sign's back end, a non-human account used to execute applications and run automated services, which had privileges to take a variety of actions within the production environment. Dropbox said the threat actor got in using an access token that had been compromised, and did not say how that token was obtained. A later investigation, which the company closed on 21 June 2024, placed the first access on 19 April and the last observed activity on 20 April.
All Dropbox Sign account holders had names, email addresses and account settings exposed. For a subset, phone numbers, hashed passwords and authentication material including API keys, OAuth tokens and multi-factor authentication settings were also involved. People who had only received or signed a document without opening an account had names and email addresses exposed. Dropbox said it found no evidence the attacker reached the contents of accounts, meaning agreements and templates, or any payment information.
Dropbox expired user passwords, logged out connected devices, rotated API keys and OAuth tokens, and temporarily restricted the Sign API to signature requests while customers regenerated keys. It engaged outside forensic investigators and notified law enforcement and data protection regulators. The company told the SEC it did not expect the incident to have a material effect on its operations or finances, while flagging possible litigation and regulatory scrutiny as risks.