The 2014 'Dropbox hack' that wasn't: leaked credentials and ransom
October 2014
Hackers claimed to have stolen nearly 7 million Dropbox logins, posted batches on Pastebin, and demanded Bitcoin — but the credentials came from other breached services, not Dropbox itself.
What happened
In October 2014 anonymous users posted hundreds of Dropbox username-and-password pairs to Pastebin and solicited Bitcoin donations to release more. TechCrunch reported at the time: 'After last week's Snapchat photo hack, it's cloud storage provider Dropbox's turn in the unsavory insecurity spotlight. An anonymous Pastebin user has claimed to have compromised almost seven million Dropbox account credentials (emails and passwords), posting the first 400 direct to Pastebin with a call for Bitcoin donations to leak more.'
Dropbox investigated and said its systems had not been breached. In a post titled 'Dropbox wasn't hacked,' it wrote: 'Recent news articles claiming that Dropbox was hacked aren't true. Your stuff is safe. The usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox. Attackers then used these stolen credentials to try to log in to sites across the internet, including Dropbox. We have measures in place to detect suspicious login activity and we automatically reset passwords when it happens.' When a second batch of credentials surfaced the next day, Dropbox added an update to the same post: 'A subsequent list of usernames and passwords has been posted online. We've checked and these are not associated with Dropbox accounts.'
TechCrunch's own reporting reached a similar conclusion, noting that the follow-up leaks 'do not appear to be genuine' and that the underlying cause looked like password reuse rather than any compromise of Dropbox's own systems: 'If it's a case of simple password cross-pollination (i.e. web users reusing the same login credentials) across multiple services then Dropbox's claim that its servers have not been hacked does technically stand up. However the end result — user accounts compromised — is the same.'
Impact
Even though Dropbox's own systems were not breached, the incident showed how the company's brand could be weaponized and how password reuse left its users exposed regardless of Dropbox's internal security. It became a recurring talking point in arguments for two-factor authentication and against single-factor cloud logins.
Sources
- 01Dropbox Blog — 'Dropbox wasn't hacked'Official / Dropbox2014
- 02