Skip to main content

A hack from 2012 haunts Dropbox as details emerge on 68 million accounts

Dropbox Notes
aradaphotography/Shutterstock
Last week Dropbox advised users with accounts from around or before 2012 to change their passwords. That’s because a hack around four years ago compromised some 68 million accounts, and it’s only now that the extent of the attack is becoming clear.

Dropbox knew of the original hack, reports Motherboard, but was not aware of the scale. The site said it obtained a 5GB copy of the compromised data that contained email addresses and hashed passwords of more than 68 million accounts. An unnamed “senior Dropbox employee” verified the authenticity of the data.

Recommended Videos

At the same time Troy Hunt, the security pro behind haveibeenpwned.com, backed up these claims. He wrote that this database is not a collection of credentials that just happen to work on Dropbox but rather the result of a very real hack.

“There is no doubt whatsoever that the data breach contains legitimate Dropbox passwords, you simply can’t fabricate this sort of thing,” he said, but added that he believed Dropbox were handling the situation very well by force resetting users’ passwords.

Patrick Heim, Dropbox’s head of trust and security, said all potentially affected users have been notified. He stated it was a precautionary measure, but did not specify how many passwords were reset by the company.

It was in a later statement that Dropbox clarified: “We can confirm that based on our intelligence number we have seen is in the 60+ mil range.”

Heim further warned users to change their passwords on other sites if they have reused their Dropbox credentials, and even if they use two-factor verification. The company added that it has seen no evidence of malicious activity on affected accounts.

The passwords that were stolen were hashed to protect them from being revealed to an attacker. However, they were not all hashed equally. Reportedly, 32 million of 68 million passwords were hashed by bcrypt, which is considered quite strong, but the remainder were hashed with SHA-1, which is gradually becoming outdated and easier to crack.

If you’re a Dropbox user that had an account in 2012, you should have received a password reset notification. If not, you may want to change your password anyway to be on the safe side, and certainly change any re-used passwords on other sites.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Here’s why it is a good time to buy a monitor
Pair of monitors on a desk with a monitor arm.

Planning to get your hands on one of the best monitors for your workstation or gaming PC? There’s good news. Due to the declining demand for computer monitors, we could soon witness a welcome price reduction for consumers.

As per a report by DigiTimes, industry analysts suggest that the market for monitors -- particularly standard LCDs -- has been impacted by the rise of more affordable OLED alternatives and a slowdown in overall consumer demand. This shift in demand has left manufacturers with surplus inventory, which they are expected to discount more aggressively through the end of 2024 to drive sales. A similar pattern is being observed with laptop displays as the demand for entry-level notebook panels is also declining.

Read more
Samsung’s Vision Pro competitor is one step closer to a 2025 release
The Sony XR headset being worn on a someone's face.

Samsung's TM Roh shares XR plans at the 2023 Galaxy Unpacked event. Samsung

Samsung has confirmed it still has plans to release an XR device that will be available sometime next year.

Read more
Intel CEO says that Lunar Lake was ‘a one-off’
Intel CEO Pat Gelsinger presents Intel's roadmap including Arrow Lake, Lunar Lake, and Panther Lake.

Intel's CEO Pat Gelsinger talked about the future of its top processors in the company's latest earnings call. Apart from reporting a huge $16.6 billion loss, the earnings call revealed a bit about next-gen products like Panther Lake and Nova Lake. According to Gelsinger, those two generations of laptop CPUs will not follow in Lunar Lake's footsteps. In fact, Gelsinger referred to Lunar Lake as "a one-off."

Lunar Lake introduced a first for Intel -- at least in terms of consumer processors. It came with on-package LPDDR5X memory, which brought Intel closer to some of the highly successful M chips manufactured by Apple. On-package memory can improve data transfer speeds and boost efficiency, and Lunar Lake was also proven to have solid battery life. Despite these benefits, Intel isn't going to give Lunar Lake a direct successor.

Read more