What happened
Dropbox disclosed that on 14 October 2022 GitHub alerted it to suspicious activity that began the previous day. Attackers had emailed Dropbox engineers impersonating the CI/CD provider CircleCI, harvested GitHub credentials and one-time passcodes through a fake login page, and copied 130 private repositories. Dropbox said no user content, passwords or payment information was accessed.
How the deception worked
The lure imitated CircleCI, a service Dropbox developers used and which legitimately prompts users to sign in with GitHub, so the request to authenticate looked routine. The phishing page collected the GitHub username, password and the time-based one-time passcode, which the attacker replayed immediately to establish a session. With developer access they cloned 130 private repositories containing modified third-party libraries, internal prototypes, and some security team tools and configuration files, along with a few thousand names and email addresses for employees, current and past customers, sales leads and vendors. Dropbox rotated credentials and moved to accelerate its rollout of hardware security keys.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Time-based one-time passcodes are phishable in real time; WebAuthn keys on source-control accounts, and machine-to-machine tokens scoped per repository, remove both halves of this attack.
Sources (3)
- 130 Dropbox code repos plundered after successful phishing attackHelp Net Security·helpnetsecurity.comOpen ↗
- Dropbox Suffers Data Breach From Phishing Attack, Exposing Customer and Employee EmailsGitGuardian·blog.gitguardian.comOpen ↗
- Dropbox confirms serious security breach in which hackers stole code from 130 GitHub repositoriesBetaNews·betanews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.