Dropbox
Disclosed Nov 1, 20223 years agoUnverified
Phishing attack lets hacker steal 130 Dropbox GitHub repositories
Dropbox said a threat actor phished employee credentials, accessed one of its GitHub organizations and copied 130 code repositories. It said the code contained some credentials, mainly API keys used by developers, but no customer content or core app code.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Nov 1, 2022 |
| Attack | Phishing |
| Data exposed | Source code, API keys |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Dropbox discloses breach after hacker stole 130 GitHub repositoriesbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Nov 1, 2022 |
Other breaches at Dropbox
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Lenovo ID verification flaw let attacker access about 5,000 Dropbox accountsSep 23 weeks agoVendor breachUnverified | Sep 23 weeks ago | Vendor breach | Tech | Unverified | 5,000 |
| Material cybersecurity incident reported to the SEC (8-K Item 1.05)May 1, 20242 years ago | May 1, 20242 years ago | Not stated | Tech | Confirmed | Unknown |
| Stolen employee password leads to Dropbox user email theft; 68M credentials later leakJul 31, 201214 years agoCredential stuffing | Jul 31, 201214 years ago | Credential stuffing | Tech | Confirmed | 69M |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.