Dropbox reveals it was victim of a phishing attack, says no passwords were stolen

The file hosting platform Dropbox has revealed that they were recently the target of a phishing attack that saw hackers successfully steal some of the code that they stored on Github. However, they were also quick to state that no content, passwords or payment information were compromised, and that the issue they encountered was resolved quickly.

According to Dropbox, they were alerted by Github on 14 October that they noticed some suspicious behaviour happening. They then checked it out for themselves and saw that a threat actor that was also pretending to be CircleCI, another software company, had gained access to one of their Github accounts. This threat actor then managed to access some code and API keys used by Dropbox developers, along with some data that includes a few thousand names and email addresses of Dropbox employees, current and past users, sales leads and vendors.

“We were recently the target of a phishing campaign that successfully accessed some of the code we store in GitHub. No one’s content, passwords, or payment information was accessed, and the issue was quickly resolved. Our core apps and infrastructure were also unaffected, as access to this code is even more limited and strictly controlled. We believe the risk to customers is minimal,” – Dropbox

Once they realised that their Github accounts were compromised, Dropbox’s security teams took immediate action and cut off the threat’s access to their data. They also reviewed their security logs to ensure no other abuse of their data had occcurred. Dropbox has since began notifying all users affected, and will also be engaging with third party forensic experts to verify what they found and then report the incident to authorities.

As for now, Dropbox has apologised to their users and have stated that they’ll be speeding up the adoption of WebAuthn, a credential management API that can better authenticate the right users in an effort to reduce the future risk of being phished. They also state that any Dropbox users who notice suspicious behaviour on their Dropbox account should also report it to them here.

[ SOURCE ]

Recent Posts

Gentari deploys 220kW DC Charger at Petronas Mutiara Damansara

If you need to top up your EV quickly around Mutiara Damansara, Gentari has deployed…

23 minutes ago

BYD Atto 3 Performance AWD now in Malaysia: Limited to just 69 units, priced at RM149,800

BYD Sime Motors has officially launched the BYD Atto 3 Performance, marking the third variant…

1 hour ago

Asus ROG G1000 flagship gaming desktop arrives in Malaysia with Ryzen 9 9950X3D and RTX 5080, priced at RM29,999

If you are looking for a pre-built gaming rig with serious horsepower and have a…

1 hour ago

EV registrations jump 155% YoY to record 8,833 units in August, 11.43% of Malaysia TIV

Malaysia recorded an all-time high of 8,833 electric vehicle (EV) registrations in August 2026, according…

1 hour ago

GSMA: Southeast Asia mobile emissions rise 20% due to poor renewable energy access

Mobile operators across Asia Pacific are struggling to meet their climate goals despite growing commitments,…

9 hours ago

Apple Watch Ultra 4: Upgraded GPS tracking, 50-hour battery life, priced from RM3,699

Apple has officially unveiled the Apple Watch Ultra 4 alongside the iPhone Duo, iPhone 18…

19 hours ago

This website uses cookies.