Spam Sent to Dropbox E-mail Addresses Leads to Speculation About Breach

An odd spike in spam lead some users of Dropbox to wonder if the service had suffered a breach. The incident occurred when users of the cloud-locker service discovered that e-mail addresses they had uniquely made for those accounts received a sudden uptick in spam e-mails from various sources. This lead to threads being posted in the Dropbox forums and speculation rising on sites such as Reddit.

Steve Ragan from SecurityWeek ran down the domains and advertisements that many of the spammers were using to target the Dropbox users in question,

InBoxes targeted by the spammer are seeing advertisements for EU Dice, Euro Gaming Palace, Premier Players Club, Vegas Virtual, SP Casino, and Best2day Support, and this is only list of the most mentioned spammed topics.

Commenting on the reports, Cloudmark said that recent data from their Global Threat Network showed 364 different domains in use by this spammer. “Some of the domains point to an IP address shared with domains that have been seen by our system in prior spam campaigns as far back as 2008. So this is a long way from a new campaign,” the anti-spam company explained.

As this occurred on Wednesday, Dropbox has been quick to begin an investigation of the incident.

“We wanted to update everyone about spam being sent to email addresses associated with some Dropbox accounts. We continue to investigate and our security team is working hard on this. We’ve also brought in a team of outside experts to make sure we leave no stone unturned,” a Dropbox staffer said on the user forums.

“While we haven’t had any reports of unauthorized activity on Dropbox accounts, we’ve taken a number of precautionary steps and continue to work around the clock to make sure your information is safe. We’ll continue to provide updates.”

So far UK and EU users appear to have been hit the hardest.

Dropbox has been in the news over the years due to the quality of the security placed on files saved in their personal-clouds via the service. For example, the FTC threatened an investigation into the service over expectations of privacy of user files—particularly because Dropbox employee’s have access to the encryption keys used to store the files in the cloud. And when the cloud-locker updated their Terms of Service in July 2011, it caused a row about how private user files are accessible or commutable by such services. The situation of privacy and security with cloud-based file lockers and other services is still an evolving field of scrutiny and question.

However, the swift response from Dropbox to bring in an outside source to determine if the spam event is because of a breach on their end feels heartening. It means that the cloud service is sensitive to customer concerns about the integrity of their files.

About Kyt Dotson

Technology and civilization walk hand in hand and civilization is nothing without the skin of society, brushing up against itself, speaking strange nothings across dimly lit avenues and computer screens. If we're going to understand ourselves in this digital era, it will be through watching the adoption of technology by people to express themselves as people. I am an anthropologist and an author of science fiction and fantasy--and with my technology, I hope to open up new and exciting worlds that will not just enlighten the humanity of my friends and fans but also educate and enhance the expression of their own personhood. Find more of my work on Google+.
Post comment as twitter logo facebook logo
Sort: Newest | Oldest
fundinggates 7 pts

Oh yikes, good to know. We're avid dropbox users but talk about quite a place to be hit... But I'm glad you commented on dropbox's response. They're a great company. Thanks for sharing Kyt!

 

Best,

Meredith

http://www.fundinggates.com

Kyt Dotson 11 pts moderator

 fundinggates I use Dropbox for a lot of personal and business-related purposes -- but I'm also cognizant of the privacy issues, as a result, I put anything that I need protected into a TrueCrypt volume and while I store passwords in the cloud, they're also heavily encrypted via other tools.

Trackbacks

  1. [...] Spam to Dropbox E-mail Addresses Leads to Speculation About Breach Read more from Test [...]

  2. [...] incident revalidated that.  Apparently users of the popular cloud storage service have been receiving unusually high amounts of spam lately. A breach at Dropbox is a very likely explanation for the problem. Issues like these will drive [...]

  3. [...] of a breach at Dropbox fueled a great deal of speculation when clients of the cloud-storage service discovered an increase in spam coming to e-mail addresses they registered there. To their credit, Dropbox quickly go the ball rolling on an investigation into what happened and [...]

  4. [...] month Dropbox users started seeing more spam in their inboxes, including many who have opened e-mail accounts exclusively to sign up for a service. That led to [...]