Hey guys, just heads up to change your passwords!, here is the story on the hacker news Link

Dani AI

Generated

Thanks to for the heads-up and to for the correction. The Pastebin claim that “nearly 7 million” Dropbox accounts were stolen appears to have been a credential-stuffing style dump: attackers reuse credentials taken from other breaches and try them across many services. Dropbox’s security team published a short explanation, and the technique is well documented as “credential stuffing.” OWASP: Credential stuffing. ()

Practical steps to take now: check whether your email appears in any known breaches using a breach-search site such as Have I Been Pwned, change any passwords that you reuse, and enable multi-factor authentication on sensitive accounts (Dropbox documents how to turn on 2-step verification). If you use the same password across services, change the duplicates first. When resetting, go directly to the service’s website (don’t click links in unsolicited emails). (haveibeenpwned.com)

A bit of context for readers arriving later: these “credential dumps” can resurface for years. A separate, larger resurfaced incident tied to old Dropbox data (reported in 2016) showed how ancient breaches still pose risk and prompted mass resets — a reminder that password hygiene is a long-term requirement. [WIRED coverage of the 2016 resurfacing]. (wired.com)

Short checklist: use a reputable password manager to generate and store unique passwords; enable 2FA (authenticator app or security key preferred); review and revoke unknown devices or app tokens from your account’s security page; watch for phishing; and run periodic checks with breach-notification services. These measures reduce the chance that a reused or leaked credential will give an attacker access.

Actually Dropbox not hacked, and the majority of the logins posted so far either are not related to Dropbox or are from inactive accounts. Looks like yet another case of someone posting a database of stolen credentials that were being reused by people across sites and services, and the 'hacker' was trying all the major players to see if anything hit. Dropbox states it had already reset passwords on all accounts it had identitied at being at potential risk from this particular non-exploit.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.