Data Breaches

Dropbox discloses breach after hacker stole 130 GitHub repositories

0

Dropbox disclosed a security breach in which the threat actors gained unauthorized access to 130 of its source code repositories on GitHub by using employee credentials stolen in a phishing attack.

The company found that the attackers breached the account on October 14 when GitHub notified it of suspicious activity that started a day before the alert was sent.

Dropbox stated that their investigation has found that the code accessed by this threat actor contained some credentials—primarily, API keys—used by Dropbox developers.

The code and the data around it also included a few thousand names and email addresses belonging to Dropbox employees, current and past customers, sales leads, and vendors.

Dropbox which offers cloud storage, data backup, and document signing services, among others, has over 17.37 million paying users and 700 million registered users.

The breach resulted from a phishing attack that targeted multiple Dropbox employees using emails impersonating the CircleCI continuous integration and delivery platform and redirecting them to a phishing landing page where they were asked to enter their GitHub username and password.

On the same phishing page, the employees were also asked to “use their hardware authentication key to pass a One Time Password (OTP).”

Once the attackers stole the Dropboxers’ credentials, they gained access to one of Dropbox’s GitHub organizations and stole 130 of its code repositories.

The company stated that these repositories included their own copies of third-party libraries slightly modified for use by Dropbox, internal prototypes, and some tools and configuration files used by the security team.

However, they did not include code for their core apps or infrastructure. Access to those repositories is even more limited and strictly controlled.

Dropbox added that the attackers were not able to access customers’ accounts, passwords, or payment information in the breach.

As a result of this incident, Dropbox is working on securing its entire environment using WebAuthn and hardware tokens or biometric factors.

Image Credits : Security Intelligence

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

See Tickets data breach went undetected for 2.5 years

Previous article

OPERA1ER hackers targeted financial organizations in Africa

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *