May 3, 2024, 1:42 a.m. | /u/LocationEfficient161

Privacy & Freedom in the Information Age www.reddit.com

DropBox states an unknown Threat Actor(s) was able to access user e-mails, usernames, account settings, and in some scenarios hashed passwords, phone numbers, API keys, OAuth tokens, and MFA.

Actual SEC filing [https://www.sec.gov/Archives/edgar/data/1467623/000146762324000024/dbx-20240429.htm](https://www.sec.gov/Archives/edgar/data/1467623/000146762324000024/dbx-20240429.htm) and DropBox announcement [https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign](https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign)

access account actor api api keys dropbox dropbox sign hashed passwords incident keys mails mfa numbers oauth passwords phone phone numbers privacy security security incident settings sign states threat threat actor tokens usernames

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Operations Manager-West Coast

@ The Walt Disney Company | USA - CA - 2500 Broadway Street

Vulnerability Analyst - Remote (WFH)

@ Cognitive Medical Systems | Phoenix, AZ, US | Oak Ridge, TN, US | Austin, TX, US | Oregon, US | Austin, TX, US

Senior Mainframe Security Administrator

@ Danske Bank | Copenhagen V, Denmark