You might see that the Dropbox Community team have been busy working on some major updates to the Community itself! So, here is some info on what’s changed, what’s staying the same and what you can expect from the Dropbox Community overall.
Forum Discussion
AST2
7 months agoHelpful | Level 6
Connection with Epson Printer just randomly stopped
Hi All,
Just out of nowhere when we scan from our epson printers (we have two) it no longer writes to drop box. See error message email below;
I have already carried out the fo...
- 7 months ago
It seems that Epson fixed the issue on their end:
- Scan to Cloud disaster recovery notice (Wednesday, May 8th, 2024 11:00 (UTC))
Thank you for using our products regularly.
We apologize for any inconvenience caused to our users.
An issue occurred that made Dropbox unavailable during the following times.- From May 1st, 2024 04:00 to May 8th, 11:00 (UTC)
- Scan to Cloud disaster recovery notice (Wednesday, May 8th, 2024 11:00 (UTC))
MMarchincin
Helpful | Level 6
It looks like there was a security issue with Dropbox sign. It looks like it happened at the end of the month (april) coincidentally. read below. Not sure if this has anything to do with what we are experiencing.
On April 24th, we became aware of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. Upon further investigation, we discovered that a threat actor had accessed Dropbox Sign customer information. We believe that this incident was isolated to Dropbox Sign infrastructure, and did not impact any other Dropbox products. We’re in the process of reaching out to all users impacted by this incident who need to take action, with step-by-step instructions on how to further protect their data. Our security team also reset users’ passwords, logged users out of any devices they had connected to Dropbox Sign, and is coordinating the rotation of all API keys and OAuth tokens. Please read on for additional details and an FAQ.
On April 24th, we became aware of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. Upon further investigation, we discovered that a threat actor had accessed data including Dropbox Sign customer information such as email addresses, usernames, phone numbers and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication.
For those who received or signed a document through Dropbox Sign, but never created an account, email addresses and names were also exposed. Additionally, if you created a Dropbox Sign or HelloSign account, but did not set up a password with us (e.g. “Sign up with Google”), no password was stored or exposed. We’ve found no evidence of unauthorized access to the contents of customers’ accounts (i.e. their documents or agreements), or their payment information.
From a technical perspective, Dropbox Sign’s infrastructure is largely separate from other Dropbox services. That said, we thoroughly investigated this risk and believe that this incident was isolated to Dropbox Sign infrastructure, and did not impact any other Dropbox products.
What happened and our response
When we became aware of this issue, we launched an investigation with industry-leading forensic investigators to understand what happened and mitigate risks to our users.
Based on our investigation, a third party gained access to a Dropbox Sign automated system configuration tool. The actor compromised a service account that was part of Sign’s back-end, which is a type of non-human account used to execute applications and run automated services. As such, this account had privileges to take a variety of actions within Sign’s production environment. The threat actor then used this access to the production environment to access our customer database.
In response, our security team reset users’ passwords, logged users out of any devices they had connected to Dropbox Sign, and is coordinating the rotation of all API keys and OAuth tokens. We reported this event to data protection regulators and law enforcement.
torero
7 months agoHelpful | Level 6
Hello MMarchincin ,
Thank you for your input. This is most probably linked to our issue. I am not sure how you relate to the customer service from Dropbox as your messages indicates "WE". Please keep us posted if you have information on when this will get solved. We are in a mess for efficient work. Thank you.
- MMarchincin7 months agoHelpful | Level 6
I am not associated with dropbox but a user who is frustrated and ran across that in my search.
About Integrations
Find solutions to issues with third-party integrations from the Dropbox Community. Share advice and help members with their integration questions.
Need more support
If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X or Facebook.
For more info on available support options for your Dropbox plan, see this article.
If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!