Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Dropbox GitHub Breach 2022: How a Fake CircleCI…
Breach analysis Incident: 1 Nov 2022

Dropbox GitHub Breach 2022: How a Fake CircleCI Login Exposed 130 Repositories and Developer API Keys

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 8 min read
Category: NHI
Attack route: Social engineering Stolen credentials Identities: API key
On this page

On 1 November 2022, Dropbox disclosed that an attacker had copied 130 of its GitHub repositories after phishing employees with emails that impersonated CircleCI, a CI/CD service used internally by Dropbox. The fake CircleCI login page asked for GitHub usernames and passwords, and then for a one-time password from employees' hardware authentication keys, which the attacker relayed to sign in. Activity began on 13 October 2022 and GitHub alerted Dropbox the next day. The repositories held copies of third-party libraries, internal prototypes and security team tools and configuration files. Dropbox says the code contained credentials, mainly API keys used by its developers, plus a few thousand names and email addresses of employees, customers, sales leads and vendors. Core apps and infrastructure code were not included. Dropbox disabled the access the same day, rotated the exposed developer credentials and says it found no evidence of successful abuse.

Key takeaways

  • Dropbox says a phishing campaign impersonating CircleCI captured GitHub credentials and one-time passwords, letting an attacker copy 130 internal repositories in October 2022.
  • The copied code contained credentials, primarily API keys used by Dropbox developers, according to Dropbox; a source code repository became a store of machine credentials for whoever cloned it.
  • The repositories also held a few thousand names and email addresses of employees, customers, sales leads and vendors, but not code for Dropbox's core apps or infrastructure.
  • Dropbox rotated the exposed developer credentials and says it found no evidence of successful abuse; it said it believed the risk to customers was minimal.
  • The identity lesson: secrets in source code are exposed whenever the repository is, so keeping API keys out of code matters as much as protecting the people who can clone it.

At a glance

OrganisationDropbox
WhenActivity began 13 October 2022; GitHub alerted Dropbox on 14 October 2022; Dropbox disclosed on 1 November 2022
AttackerUnknown; Dropbox has not attributed the campaign
Entry pointPhishing emails impersonating CircleCI that led employees to a fake login page collecting GitHub credentials and one-time passwords
Identities abusedEmployee GitHub accounts (human); API keys and other developer credentials stored in the copied repositories (machine)
Impact130 repositories copied, including developer API keys and a few thousand names and email addresses; no evidence of successful abuse per Dropbox
CategoryNHI. Incident class: confirmed NHI breach (phished access used to steal repositories containing developer API keys)

What happened

In its post "How we handled a recent phishing incident that targeted Dropbox", the Dropbox Security Team explained that in early October 2022 several employees received emails impersonating CircleCI. GitGuardian describes CircleCI as a CI/CD platform used internally by Dropbox, and a person can sign in to CircleCI with GitHub credentials, which made the lure believable. Some of the emails were quarantined, but others reached inboxes. They directed employees to a fake CircleCI login page, where employees entered their GitHub username and password and then used "their hardware authentication key to pass a One Time Password (OTP) to the malicious site."

With those credentials and codes the attacker reached one of Dropbox's GitHub organisations and copied 130 repositories. GitHub detected the activity and told Dropbox on 14 October 2022, the day after it began. Dropbox described the repositories as copies of third-party libraries it had modified, internal prototypes and some tools and configuration files used by its security team. "Importantly, they did not include code for our core apps or infrastructure," Dropbox wrote.

The NHI part of the story is what the code contained. Dropbox said the code accessed by the attacker held some credentials, primarily API keys used by Dropbox developers. It also contained a few thousand names and email addresses of employees, customers, sales leads and vendors. Dropbox stressed that the attacker never had access to the contents of anyone's Dropbox account, to their passwords or to payment information.

Dropbox disabled the attacker's access on the day it was alerted, rotated the exposed developer credentials, brought in outside forensic experts and informed regulators and law enforcement. "We also reviewed our logs, and found no evidence of successful abuse," it said, adding: "We believe the risk to customers is minimal." Dropbox said it was speeding up its move to WebAuthn: "Soon, our whole environment will be secured by WebAuthn with hardware tokens or biometric factors." GitGuardian's Mackenzie Jackson noted that Dropbox had not said which systems the exposed keys could reach, and wrote that "As this breach shows, plain text secrets and credentials in source code are a huge problem."

Timeline

DateEvent
October 2022Dropbox employees receive phishing emails impersonating CircleCI.
13 October 2022The attacker begins accessing Dropbox's GitHub organisation and copying repositories.
14 October 2022GitHub alerts Dropbox, which disables the attacker's access the same day and then rotates the exposed developer credentials.
1 November 2022Dropbox discloses the incident publicly.
2 November 2022GitGuardian and Malwarebytes publish analyses of the breach.

How it happened: the identity attack path

  1. Trusted service impersonated. The attacker sent emails posing as CircleCI, a CI/CD platform Dropbox used and one that accepts GitHub sign-in.
  2. Credentials and OTP relayed. A fake CircleCI login page captured GitHub usernames and passwords, then a one-time password generated by the employee's hardware key, which the attacker used in real time.
  3. Repository access. The attacker used the employee access to reach a Dropbox GitHub organisation and copied 130 repositories.
  4. Machine credentials collected. The copied code contained credentials, mainly developer API keys, along with contact details of employees, customers, sales leads and vendors.
  5. Detection and rotation. GitHub flagged the activity a day later; Dropbox cut off access and rotated the exposed API credentials.

Impact

  • Confirmed: 130 repositories copied, containing developer API keys and other credentials, and a few thousand names and email addresses.
  • Not affected: core app and infrastructure code, user account contents, passwords and payment information, according to Dropbox.
  • Misuse: Dropbox says its log review found no evidence of successful abuse of the credentials, and it rotated them.
  • Potential: the stolen names and email addresses could support follow-up phishing, a risk GitGuardian highlighted; the reach of the API keys was not disclosed.

What this means for NHI governance

Dropbox's entry point was human: employees were phished, and the one-time passwords their hardware keys generated could still be relayed. The reason this breach sits on an NHI list is what happened next. Developer API keys were stored in the repository code, so the attacker obtained machine credentials as a side effect of cloning repositories. The breach followed the same pattern as other 2022 repository thefts, including the Slack GitHub breach and the GitHub code signing certificate theft.

Two controls would have changed the outcome. Phishing-resistant authentication such as WebAuthn binds the login to the real site, so a fake page cannot relay it. And secrets kept in a vault rather than in code would have left the attacker with source code but no keys. Dropbox's decision to rotate every exposed credential straight away was the right response. Our Secrets Management Guide and Passwordless and Passkeys Guide cover both.

Recommendations

  • Keep API keys and other secrets out of source code. Store them in a secrets manager and inject them at runtime, including in prototypes and internal tools. See our Secrets Management Guide.
  • Scan repositories and their full history for secrets. Removing a key from the latest commit does not remove it from history; scan both and rotate what you find.
  • Rotate every credential in a stolen repository. Assume all secrets in copied code are compromised, as Dropbox did, and check logs for their use. See the Leaked Credential Response Playbook.
  • Use phishing-resistant authentication for code platforms. One-time passwords can be relayed; WebAuthn and passkeys cannot be replayed to a fake site. See our Passwordless and Passkeys Guide.
  • Alert on bulk repository cloning. Unusual clone volume from one account is a strong signal; GitHub's alert is what started Dropbox's response. See our ITDR Guide.
  • Train staff on lures that impersonate developer tools. CI/CD and code platforms are trusted brands for engineers, which makes them effective phishing cover.

Frequently asked questions

How was Dropbox hacked in 2022?

Attackers sent Dropbox employees phishing emails impersonating CircleCI. A fake login page captured their GitHub credentials and hardware-key one-time passwords, which the attacker used to copy 130 Dropbox GitHub repositories in October 2022.

Were Dropbox user files or passwords exposed?

No. Dropbox says the attacker never had access to the contents of anyone's Dropbox account, their passwords or payment information, and that the repositories did not include code for its core apps or infrastructure.

What credentials were in the stolen Dropbox repositories?

Dropbox says the code contained some credentials, primarily API keys used by Dropbox developers. It rotated those credentials and reported no evidence of successful abuse.

CircleCI Breach 2023 · Slack GitHub Breach 2022 · GitHub Code Signing Certificate Theft 2022 · Secrets Management Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Repository thefts keep turning into credential thefts because API keys live in code. We help teams find the secrets already sitting in their repositories, move them into managed storage and set up rotation so a stolen repository does not mean stolen access. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org