Dropbox account passwords posted online and millions more might follow


If you haven't activated two-factor authentication on Dropbox yet, you may want to do so now, just in case you end up finding your credentials posted on the internet. A document posted on pastebin earlier contains 400 Dropbox usernames and passwords, which the poster claims are just a tiny fraction of a massive hack that compromises up to 7 million accounts. The poster has been asking for Bitcoin donations in exchange for more accounts, and by the looks of it, he got enough money, at least, to post another batch of log-in credentials within the same day. At the moment, it's still unclear how the hacker(s) got a hold of the usernames and passwords, but the cloud service told Engadget that Dropbox itself has not been hacked.


"These usernames and passwords were unfortunately stolen from other services and used in attempts to log in to Dropbox accounts," a spokesperson told us. "We'd previously detected these attacks and the vast majority of the passwords posted have been expired for some time now. All other remaining passwords have been expired as well." Still want to ensure your account's safety anyway? Head over to the Dropbox's detailed explanation on how to turn on two-step authentication. Hopefully, when you log in to do so, the service has also restored any file a recent bug might have deleted from your folder.



Incidentally, all those "Dropbox" dumps on Pastebin result in notifications sent to @haveibeenpwned subscribers: https://t.co/mtuwpaQ7k1


- Troy Hunt (@troyhunt) October 14, 2014

Filed under: ,


Comments


Via: TheNextWeb


Source: Pastebin






from Engadget Full RSS Feed http://ift.tt/1yxappB

via http://ift.tt/1yxappB
Share on Google Plus
    Blogger Comment