File hosting service Dropbox has disclosed a major security breach which allowed threat actors to hack its GitHub code repositories.
Hackers gained unauthorised access to 130 repositories after a phishing attack gave them access to a Dropbox GitHub account using employee credentials.
Dropbox said it discovered the breach on the 14th of October when it was notified by GitHub of suspicious activity that started one day before the alert was sent.
In a blog post, the company said noted that no content, passwords, or payment information were accessed by the hackers, and the issue was quickly resolved.
Additionally, the firm’s core apps and infrastructure were unaffected as Dropbox has strict controls in place to stop access.
“We believe the risk to customers is minimal. Because we take our commitment to security, privacy, and transparency seriously, we have notified those affected and are sharing more here,” the post read.
“To date, our investigation has found that the code accessed by this threat actor contained some credentials—primarily, API keys—used by Dropbox developers,” Dropbox continued.
“The code and the data around it also included a few thousand names and email addresses belonging to Dropbox employees, current and past customers, sales leads, and vendors (for context, Dropbox has more than 700 million registered users).”
A successful phishing attack which targeted multiple Dropbox employees used emails impersonating the CircleCI continuous integration and delivery platform. The correspondence redirected employees to a phishing landing page where they were asked to enter their GitHub username and password.
Additionally, the employees were prompted to use their hardware authentication key to pass a One Time Password (OTP), giving the hackers access to the repositories.
Dropbox said: “These repositories included our own copies of third-party libraries slightly modified for use by Dropbox, internal prototypes, and some tools and configuration files used by the security team.”
On the same day that the firm was informed of the suspicious activity, it disabled the access gained by the threat actors.
“Our security teams took immediate action to coordinate the rotation of all exposed developer credentials and determine what customer data—if any—was accessed or stolen. We also reviewed our logs and found no evidence of successful abuse.”
The company hired forensic experts from outside the organisation to verify its findings and reported their results to the appropriate regulators and law enforcement.
Recommended
- Five things you need to know about the OpenSSL patch
- Royal Mail data breach: Here’s what you need to know
- Calls for probe after reports that Liz Truss’ phone was hacked
In response to the incident, Dropbox said it is working on securing its entire environment using WebAuthn and hardware tokens or biometric factors. Prior to the hack, the firm was in the process of adopting this more phishing-resistant form of multi-factor authentication.
“We’re sorry we fell short and apologize for any inconvenience. One way we hope to prevent a similar incident from occurring is by accelerating our adoption of WebAuthn,” Dropbox added.
Chris Hauk, Consumer Privacy Advocate at Pixel Privacy commented: “Phishing attempts like this illustrate why this type of attack continues to be effective. When even IT professionals can fall for phishing attacks, is there any hope in attempting to educate the average user as to the dangers of phishing emails and messages?
“Unfortunately, the bad actors of the world have become so skilled at crafting phishing emails that even computer pros can be fooled. Gone are the days when awkward wording and bad spelling and grammar would expose a phishing attempt.”
Back in mid-September, GitHub Security announced a similar hack was affecting its systems after learning that threat actors were targeting GitHub users by impersonating CircleCI.
Hackers were attempting to harvest user credentials and two-factor codes. While GitHub itself was not affected, the campaign was said to have impacted many victim organisations.
DIGIT Expo 2022 | Join the Conversation
DIGIT Expo is Scotland’s largest gathering of senior technology personnel and an unmissable opportunity for knowledge exchange, networking and business opportunity.
The conference will feature an array of tech leaders, innovators and world-class speakers exploring key themes such as AI, DevOps, cyber security, digital leadership, cloud computing, Web3 and data innovation.
Find out more at: www.digit-expo.com





