Dropbox says 68m user IDs stolen
WASHINGTON: Cloud-based data storage company Dropbox said Thursday that user IDs and passwords of some 68 million clients were stolen four years ago and recently leaked onto the internet.
The company said it had no indication that any of its user accounts were improperly entered, and that it had notified the users and made them reset their passwords on the accounts.
The company learned of the theft of the data only two weeks ago after the 68m user credentials were posted online, but indicated it still does not know how or by whom.
â€œThe list of email addresses with hashed and salted passwords is real, however we have no indication that Dropbox user accounts have been improperly accessed. Weâ€™re very sorry this happened and would like to clear up whatâ€™s going on,â€ the company said in an emailed statement.
Dropbox believes the credentials were taken in 2012. After learning of the problem, it said, â€œwe then emailed all users we believed were affected and completed a password reset for anyone who hadnâ€™t updated their password since mid-2012.â€
â€œThis reset ensures that even if these passwords are cracked, they canâ€™t be used to access Dropbox accounts.â€
Dropbox warned users that if they had signed up for its services before 2012 and had used the same password elsewhere, they should change that as well to protect the account.
â€œAlso, please be alert to spam or phishing because email addresses were included in the list,â€ it said.
Dropbox early this year reported it had more than 500m users who store and share business files, pictures and video, and all sorts of other data on its cloud servers.
Published in Dawn, September 2nd, 2016