Feeds

Dropbox brings in crack team to probe spam leakage

Email accounts crammed with gambling site grossness

Top three mobile application threats

Dropbox has begun investigating complaints that users are receiving spam to email addresses only associated with their accounts at the file-sharing service.

The spam, sent to addresses only used for Dropbox accounts, advertises a particular gambling website, according to users on Dropbox's forum. The behaviour has sparked concerns that Dropbox's database has been harvested or otherwise compromised, although this remains unconfirmed. One other possible explanation is that a third-party app which integrates with Dropbox is to blame for the leak.

Spambots striking it lucky and randomly hitting a run of unique and private email address associated with Dropbox seems improbable, especially given the volume of users who are complaining about "Dropbox spam" on Twitter and elsewhere. Complaints on Dropbox's own forums suggest the problem is limited to European users of the file-synching service.

In response to these concerns, a Dropbox staffer said it had called in external security experts to help with an investigation into the spam run.

We wanted to update everyone about spam being sent to email addresses associated with some Dropbox accounts. We continue to investigate and our security team is working hard on this. We’ve also brought in a team of outside experts to make sure we leave no stone unturned.

While we haven’t had any reports of unauthorized activity on Dropbox accounts, we’ve taken a number of precautionary steps and continue to work around the clock to make sure your information is safe. We’ll continue to provide updates.

The Dropbox staffer added that a 30-minute outage on Dropbox's site early on Tuesday afternoon was "not caused by any external factor or third party" and apparently was not linked to the current junk mail unpleasantness. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Kingston DataTraveler MicroDuo: Turn your phone into a 72GB beast
USB-usiness in the front, micro-USB party in the back
AMD's 'Seattle' 64-bit ARM server chips now sampling, set to launch in late 2014
But they won't appear in SeaMicro Fabric Compute Systems anytime soon
Brit boffins use TARDIS to re-route data flows through time and space
'Traffic Assignment and Retiming Dynamics with Inherent Stability' algo can save ISPs big bucks
Microsoft's Nadella: SQL Server 2014 means we're all about data
Adds new big data tools in quest for 'ambient intelligence'
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.