So it’s finally been confirmed, last week Dropbox hurriedly warned its users to change their passwords if their accounts dated back prior to mid-2012. The US based cloud-based storage service suffered a wide-ranging data breach that’s said to have affected more than 68 million accounts compromised during a hack that took place roughly four years ago.
The company had previously admitted that it was hit by a hack attack, but it’s only now that the scale of the operation has seemingly come to light.
Sources on the Dark Markets database trading community made clear that they had obtained four files, totalling 5GB in size, which apparently contained e-mail addresses and hashed passwords for 68,680,741 Dropbox users.
And so without giving the matter any thought many U.K. businesses will simply continue to utilise the service without any thought. Rumours of Dropbox hacking have circulated around the dark web forever, Dropbox have continually denied most of the stories (although not all) yet U.K. companies have seemingly ignored the dangers of lapses in Dropbox’s security (even when the Safe-harbor agreement was in question and then defunct) – companies disregarded the dangers (and legalities) and recklessly continued it’s use.
Many U.K. companies whom hold ISO & UK Cyber Essential certificates throw caution to the wind when dealing with clients data – regularly transporting data on insecure laptops, data-sticks and, of course, cloud systems. The presence of a Certificate seems to lull organisations into a false sense of security, and the return to what’s convenient and comfortable takes precedence over real security protocols needed to uphold meaningful security.
And so we return to how Dropbox view such a massive breach. The tone is clear from Dropbox’s security boss Patrick Heim whom stated, it was
“not a new security incident, there is no indication that Dropbox user accounts have been improperly accessed and the password reset (last week) means they can’t be used to access Dropbox accounts. The reset only affects users who signed up for Dropbox prior to mid-2012 and hadn’t changed their password since”
Thats OK then Dropbox? Maybe U.K. Companies will now look for a more responsible, more transparent, alternative to Dropbox – perhaps even a U.K.Based, home grown alternative? As we have previously seen – legalities and insecurity fail to be important to many business owners….. so most probably not!







