Skip to main content
Breach Signal

Breach report

Cloud & SaaS

Dropbox

Dropbox employee's password reuse led to theft of 60M+ user credentials

A 2012 Dropbox intrusion that the company first described as an email leak was revealed in 2016 to have exposed hashed passwords for about 68 million users, traced to an employee reusing a password stolen in the LinkedIn breach.

Reported by TechCrunch

Records exposed

68.6M

About 68 million accounts

Scale vs. largest on file

When
2012 (surfaced 2016)
How they got in
Employee password reuse (credentials from LinkedIn breach)
Sector
Cloud & SaaS

In mid-2012, Dropbox users began receiving a wave of spam, and the company investigated. It announced that attackers had used a stolen employee password to access a project document containing user email addresses. At the time, Dropbox did not say that any user passwords had been taken. Four years later, a dataset of about 68 million Dropbox account records surfaced, and the company confirmed that the 2012 incident had also included hashed passwords.

The root cause was password reuse. A Dropbox employee had used the same password on LinkedIn, which suffered its own large breach in 2012. Attackers used that credential to get into Dropbox's corporate network, where they found and copied user credentials. Dropbox's head of trust and security later said the company had since rolled out a password manager for employees and required two-factor authentication on internal systems.

The leaked data contained email addresses and passwords protected by two methods. Roughly half, about 32 million, were hashed with bcrypt, which is designed to be slow to crack. The remainder used salted SHA-1, an older and weaker approach that Dropbox had been migrating away from. Security researcher Troy Hunt verified the data's authenticity by locating his own family's credentials, which matched the unique, randomly generated password he had used.

Before the dataset became public, Dropbox proactively forced password resets in August 2016 for users who had signed up before mid-2012 and had not changed their passwords since. The company said it had no evidence that accounts had been improperly accessed. There was no major regulatory penalty, but the episode drew criticism over the gap between the original 2012 description and the full scope revealed years later.

The Dropbox case illustrates how breaches cascade. One company's leak, in this case LinkedIn's, can provide the key to another company's systems when employees reuse passwords. It also shows the value of modern password hashing, since the bcrypt-protected portion of the data was far less useful to attackers. For organizations, it reinforced the case for enforced multi-factor authentication on internal tools; for consumers, it was another argument for unique passwords on every service.

More from the wire

More in Cloud & SaaS.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.