Home / Software & Gaming / Security / Millions of Dropbox passwords have leaked onto the web

Millions of Dropbox passwords have leaked onto the web

Way back in 2012, the Dropbox database was hacked, leading to 68 million users having their details stolen. At the time, Dropbox reported that user email addresses were in-fact stolen but didn't touch on passwords. However, this week, millions of Dropbox passwords leaked onto the web, originating from the attack several years ago.

The password dump was brought into the spotlight by Leakbase, a site dedicated to keeping tabs on user information leaks. Since then, Troy Hunt, the security researcher behind the site Have I been pwned? has had a look at the leak to verify it, discovering a record of his wife's current Dropbox details, along with a record of his old login for the service, meaning there are definitely legitimate accounts that can be affected by this.

dropbox-logo

Motherboard managed to get in touch with a spokesperson for Dropbox, who claimed that so far, there have been no signs of malicious activity on any accounts. However, a password reset will be coming to an undisclosed amount of Dropbox accounts. Around half of the passwords in the leak were protected by the bcrypt hashing algorithm, so those should be secure.

Even so,  if you have a Dropbox account, you should probably check your account and change your password. Enabling two-factor authentication should also help keep your account secure in the event of something like this happening.

KitGuru Says: This hack may have happened several years ago now but if you haven't changed your password since then, you could be affected by the leak. If you're a Dropbox user, now would be a good time to change your password to something else. 

Become a Patron!

Check Also

Chinese Steam

Valve confirms Steam has not suffered a data breach

This week, someone claimed to have breached Valve's Steam servers, coming away with account information for over 89 million users. Something seemed a bit fishy about the claim at the time, but now, Valve has confirmed that no data breach has taken place.

One comment

  1. I currently get paid something like 6 thousand-8 thousand bucks /month working on the internet. Anyone prepared to work basic freelance task for 2-5 h every day from your home and make valuable income in the same time… Then this work opportunity is for you… UR1.CA/pm79t

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!