Cybercriminals stole 130GB of private developer Github repositories with source code, credentials and API keys. Hackers gained access to one of its private GitHub accounts using employee credentials stolen in a phishing attack. Password credentials, API keys used by Dropbox developers, names and email addresses belonging to Dropbox employees, current and past customers, sales leads, and vendors (Dropbox has more than 700 million registered users).

The successful breach resulted from a phishing attack that targeted multiple Dropbox employees using emails impersonating the CircleCI continuous integration and delivery platform and redirecting them to a phishing landing page where they were asked to enter their GitHub username and password.

