Home / Software & Gaming / Security / Dropbox confirms massive password leak but denies server hack

Dropbox confirms massive password leak but denies server hack

Late last night, an anonymous Pastebin user claimed to have compromised almost seven million Dropbox account credentials, including emails and passwords. The user posted the first 400 direct to Pastebin and then proceeded to ask for Bitcoin donations before leaking more.

The original leak has been followed up on, with the leaker continuing to post hundreds of user's account credentials. However, the passwords and emails that have been posted so far don't appear to be genuine according to Dropbox, which also stressed that these leaks were the result of a third-party rather than an attack on its own servers.

dropbox-600x300

In a company blog post, titled “Dropbox wasn't hacked”, Anton Mityagin said: “Recent news articles claiming that Dropbox was hacked aren’t true. Your stuff is safe. The usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox. Attackers then used these stolen credentials to try to log in to sites across the internet, including Dropbox. We have measures in place to detect suspicious login activity and we automatically reset passwords when it happens.”

The post then goes on to encourage users to enable two-factor authentication for better account protection against unauthorized access. Additionally, the company denies that the user information that has been leaked so far is associated with any Dropbox accounts.

Discuss on our Facebook page, HERE.

KitGuru Says: Two-factor authentication is something everyone should use on cloud services like Dropbox. It doesn't look like Dropbox has been hacked but it is likely that whoever obtained the leaked credentials has led a successful phishing scam and is now hoping that the same user information has been used across multiple websites. 

Become a Patron!

Check Also

Chinese Steam

Valve confirms Steam has not suffered a data breach

This week, someone claimed to have breached Valve's Steam servers, coming away with account information for over 89 million users. Something seemed a bit fishy about the claim at the time, but now, Valve has confirmed that no data breach has taken place.

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!