Updated: Dropbox Not Hacked

Ars Technica:

A series of posts have been made to Pastebin purporting to contain login credentials for hundreds of Dropbox accounts, with the poster claiming that altogether 6,937,081 account credentials have been compromised.

Dropbox has commented that the usernames and passwords were stolen from other services:

The usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox. Attackers then used these stolen credentials to try to log in to sites across the internet, including Dropbox. We have measures in place to detect suspicious login activity and we automatically reset passwords when it happens.

When in doubt, change your password anyway, and of course, use two-factor authentication.

Update: Reddit user Makiko_ is attempting to ‘reverse hack’ the affected accounts by running a script that resets the user passwords.