View all newsletters
Receive our newsletter - data, insights and analysis delivered to you

Dropbox: password reuse caused security breach

Using the same password on multiple sites resulted in account of Dropbox employee being compromised

By Steve Evans

Dropbox has become the latest big name to disclose a security breach. It seems the cloud storage company was caught out by one of the oldest tricks in the book – people using the same password on multiple sites.

The company has confirmed that passwords stolen from other services were then used to access Dropbox accounts, including one belonging to an employee.

Whoever accessed the account stole a "project document" which contained user email addresses. That led to users noticing a surge in spam emails being sent to addresses they’d only ever used for Dropbox.

Dropbox users first began reporting an increase in spam in early July. The company was quick to respond and launched an investigation.

"Our investigation found that usernames and passwords recently stolen from other websites were used to sign in to a small number of Dropbox accounts," a statement on the Dropbox website said.

"A stolen password was also used to access an employee Dropbox account containing a project document with user email addresses. We believe this improper access is what led to the spam. We’re sorry about this, and have put additional controls in place to help make sure it doesn’t happen again," the statement added.

The company will also be revamping its security procedures by introducing two-factor authentication. This will mean that users may have to provide two forms of identification, such as a password and a one-time code that is sent to the user’s mobile phone.

Content from our partners
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline
How hackers’ tactics are evolving in an increasingly complex landscape

Users will also be able to access a page that will display all active logins. Dropbox will also be asking some users to reset their passwords. These changes will be rolled out over the next few weeks, Dropbox said.

The security industry has long been warning people against using the same password across multiple sites because, as this case demonstrates, if a hacker gains accesses to one they will try their luck at using the same credentials to get into other services.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how New Statesman Media Group may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU