Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

Tracker

Breach & Security-Incident Tracker

Every documented Dropbox security incident, data breach, and government-access concern in the archive — ordered most-severe first. Each entry links to the full sourced write-up.

Dropbox's breach history at a glance

The short, dated version. Every line below has its own sourced write-up in the archive.

  • 2011A code bug on 19 June left every Dropbox account reachable with any password for nearly four hours — Dropbox's own count came to fewer than 100 affected accounts.
  • 2012An attacker used a Dropbox employee's reused password to steal a file of roughly 68 million users' email addresses and hashed passwords — a theft whose full scale wasn't disclosed until the 2016 mass password reset.
  • 2022A phishing campaign impersonating CircleCI tricked Dropbox employees into copies of 130 internal GitHub repositories, plus a few thousand employee, customer, sales-lead, and vendor names and emails.
  • 2024Attackers compromised Dropbox Sign's production systems, exposing customer emails, usernames, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA data.
  • 2026A flaw in Lenovo's own sign-in verification let an attacker reach roughly 5,000 linked Dropbox accounts between 4–21 August without ever needing a Dropbox password; files were accessed in fewer than a third of them.

Two widely repeated claims aren't in that list because they weren't Dropbox breaches: a 2014 report of nearly 7 million stolen logins traced to credentials reused from other, unrelated services, and Dropbox was also wrongly named in the 2014 "Snappening" Snapchat photo leak, which actually came from a third-party app.

The archive records no new Dropbox breach disclosed in 2025 — that year's headline event was legal, not technical: a federal judge compelled the 2024 Sign-breach class action into private arbitration.

Is Dropbox safe? the full verdict.

Security & government-access incidents per year

Incidents(49)

An attacker compromised the production environment of Dropbox Sign (formerly HelloSign), exposing customer emails, usernames, phone numbers, hashed passwords, and authentication secrets including API keys, OAuth tokens, and MFA data.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
4 sources
Critical68,648,009, per Troy Hunt's independent count (Dropbox described it as 'roughly 68 million')

The 2012 breach: 68 million user credentials stolen via a reused password

An attacker used a Dropbox employee's reused password to steal a file containing roughly 68 million users' email addresses and hashed passwords — a theft whose full scale only became public in 2016.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation
2 sources
Criticalfewer than a hundred, per Dropbox's final count (initially described as 'much less than 1 percent' of accounts that logged in during the window)

The 2011 authentication bug: any password unlocked any account

For nearly four hours on 19 June 2011, a code update left Dropbox accounts accessible with any password at all — anyone could sign in to any account by typing anything.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation
9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
5 sources
HighHundreds of thousands (estimated)

Guiffre v. Dropbox: the class action over the 2024 Dropbox Sign breach

Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.

Security Incidents & Data BreachesLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation

Following the 2024 Dropbox Sign breach, affected users filed proposed class-action lawsuits accusing Dropbox of failing to secure their data and of notifying victims too slowly. Dropbox has contested the claims, arguing the exposed data poses no identity-theft risk.

Security Incidents & Data BreachesLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation

After Dropbox disclosed the April 2024 Dropbox Sign breach, affected users filed proposed class actions in federal court alleging Dropbox negligently failed to protect their data and did not give prompt, adequate notice; the claims are allegations and the consolidated litigation followed in the Northern District of California.

Security Incidents & Data BreachesLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation
2 sources
High130 internal GitHub repositories; a few thousand employee, customer, sales-lead, and vendor names and email addresses

The 2022 phishing breach: 130 internal GitHub repositories stolen

A phishing campaign impersonating the CI provider CircleCI tricked Dropbox employees into handing over credentials and 2FA codes, letting attackers copy 130 of Dropbox's private source-code repositories.

Security Incidents & Data Breaches
Read documentation

The 2018 CLOUD Act amended US law so that a US-based provider like Dropbox can be compelled to produce a user's data regardless of which country the data is physically stored in — meaning a US warrant can reach an overseas user's files.

Privacy & Encryption ConcernsLegal Actions & LawsuitsGovernment Access & Surveillance
Read documentation
2 sources
High~68 million (2012 credentials)

2016: Dropbox force-resets passwords as the 2012 breach finally surfaces

Four years after the 2012 breach, the stolen credentials surfaced in the wild, forcing Dropbox to reset the passwords of all users who had not changed them since mid-2012.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation
3 sources
Highall pre-mid-2012 users who had not changed their password

The 2016 mass password reset: forcing millions to re-secure pre-2012 accounts

When the full 2012 credential dump resurfaced in 2016, Dropbox forced a password reset on every user who had signed up before mid-2012 and never changed their password — a sweeping operational response that, for many, was the first sign anything was wrong.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

At Black Hat USA 2015, Imperva researchers showed that stealing a single synchronization token let an attacker take over a Dropbox account and read its files indefinitely — and that, in Dropbox's case, changing the password did not revoke the stolen token.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Researchers found that Dropbox's shared links to supposedly private documents could leak to third parties — exposed through browser referer headers and, in some cases, surfacing in Google search results — revealing tax returns, bank records, and business plans.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

After the 2013 PRISM disclosures named major US tech firms, Dropbox spent the following years documenting — through its own reports and advocacy — that it sits inside the same surveillance ecosystem: subject to NSLs, FISA orders and rising law-enforcement demands, with only banded, gagged disclosure permitted.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
3 sources
High0–249 national-security requests reported for 2013

National Security Letters and FISA orders: demands Dropbox can barely acknowledge

Dropbox is subject to National Security Letters and FISA orders that arrive with gag provisions barring it from disclosing even that it received them; the most it can publish is a band such as '0–249' national-security requests.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox has published a biannual Transparency Report since 2012, and its own figures document a steady, long-run climb in government and law-enforcement demands for user data — including reporting periods where US legal-process requests jumped by roughly a third.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Security researcher Christopher Soghoian filed a complaint with the U.S. Federal Trade Commission alleging that Dropbox made deceptive claims about its encryption, because Dropbox employees could in fact access users' files.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsLegal Actions & Lawsuits
Read documentation

Researcher Derek Newton showed that Dropbox's desktop client stored an unencrypted authentication token (host_id) in a local config.db file — copy that one value to another machine and you owned the victim's account, with no password and no notification.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Forcepoint X-Labs and The Hacker News documented a phishing campaign that used Dropbox URLs, not attachments, as the first link in a chain — ZIP to internet shortcut to .lnk to JavaScript to .BAT to a malicious Python package — that ultimately deployed AsyncRAT, Venom RAT, and XWorm via temporary TryCloudflare tunnels.

Security Incidents & Data Breaches
Read documentation
2 sources
Medium~68 million (2012 credentials, re-aggregated)

2024: Dropbox's 2012 credentials resurface in the 'Mother of All Breaches'

In January 2024 a 26-billion-record compilation dubbed the 'Mother of All Breaches' surfaced online — and the 68 million credentials stolen from Dropbox in 2012 were among the datasets bundled into it.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Dropbox runs industry hash-matching (PhotoDNA, NCMEC and IWF hash lists) and an unhashed-content classifier across files added to or shared on the service, reporting matches to NCMEC — a legitimate child-safety system that is also, by design, a server-side scan of users' private content.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
3 sources
Medium5,000+ attacks observed in two weeks (Check Point, Sept 2024)

Phishing pages hosted on Dropbox: the 2024 'BEC 3.0' credential-harvesting wave

Check Point recorded thousands of attacks in which criminals hosted credential-harvesting documents on Dropbox itself, so the phishing emails came genuinely from [email protected] and sailed past filters that trust the Dropbox domain.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

State-aligned hacking groups, including North Korea's Kimsuky and ScarCruft, have repeatedly used the Dropbox API as a command-and-control and data-exfiltration channel, exploiting the fact that Dropbox traffic is trusted and rarely blocked.

Security Incidents & Data BreachesGovernment Access & Surveillance
Read documentation

A tracked vulnerability in the Dropbox desktop application for Windows could strip the 'Mark of the Web' flag from synced files, weakening a key warning that protects users from running downloaded, untrusted content.

Security Incidents & Data BreachesDeveloper, API & Platform
Read documentation

ESET and Avast documented the Worok espionage group's 'DropBoxControl' backdoor, which abused the Dropbox API as its entire command-and-control channel — reading commands from, and uploading stolen data to, ordinary files in a Dropbox account.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Many third-party integrations request broad, full-Dropbox access rather than scoped, folder-limited permissions — so a single connected app, if compromised, can expose everything in an account.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsDeveloper, API & Platform
Read documentation
2 sources
Medium~19.3% of warrant-affected users in H1 2021 (indefinite gag)

Indefinite gag orders: the users Dropbox is barred from ever warning

Dropbox's own Transparency Report shows that a large share of the search warrants it receives arrive with indefinite non-disclosure orders, leaving the company unable to ever notify those users that the government took their data.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

The DropSmack proof-of-concept warned that synced Dropbox folders could be a covert C2 and exfiltration channel; multiple real malware families — including BoxCaon, Crutch and tooling used by Kimsuky — went on to abuse Dropbox folders and the Dropbox API exactly that way.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Dropbox's OAuth model historically let third-party apps request full account access, and tokens persist until revoked — so a single over-permissioned or compromised integration can read, write or delete a user's entire Dropbox without any further prompt.

Security Incidents & Data BreachesDeveloper, API & Platform
Read documentation

European courts and regulators treat data held by US providers as inherently reachable by US surveillance under FISA Section 702 and the CLOUD Act — a structural concern that applies to any US-controlled cloud service, including Dropbox, regardless of where servers sit.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
3 sources
MediumEU/EEA organizations and users

Schrems II: why EU users' files on Dropbox sit under a legal cloud

The EU's 2020 Schrems II ruling struck down the Privacy Shield framework over US surveillance, leaving EU organizations that store data with US providers like Dropbox needing extra safeguards — and unable to fully escape US legal reach.

Privacy & Encryption ConcernsLegal Actions & LawsuitsGovernment Access & Surveillance
Read documentation

Dropbox's transparency reporting centers on US legal process, but as a global service it also faces foreign-government and cross-border demands — an area where its disclosures are thinner and the CLOUD Act blurs jurisdictional lines.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Because Dropbox holds the keys to decrypt users' files, a valid legal order doesn't just get a government encrypted data it can't read — it gets readable file content. The design choice is what makes lawful compulsion effective.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Researchers revealed that Dropbox's Mac client used a user's admin password to directly edit macOS's protected TCC.db permissions database, inserting itself into the Accessibility list — a privacy/trust list that grants near-total control over the machine — without a clear, informed prompt.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsReliability & Data Loss
Read documentation

Dropbox runs every uploaded image and video through hash-matching systems such as Microsoft's PhotoDNA to detect known child sexual abuse material — automated scanning of users' private files that the company initially refused to explain.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
2 sources
Medium~7 million claimed by the Pastebin poster; Dropbox said the passwords had already been expired

The 2014 'Dropbox hack' that wasn't: leaked credentials and ransom

Hackers claimed to have stolen nearly 7 million Dropbox logins, posted batches on Pastebin, and demanded Bitcoin — but the credentials came from other breached services, not Dropbox itself.

Security Incidents & Data Breaches
Read documentation

On 10–11 January 2014 Dropbox went dark for roughly two hours after an internal maintenance error, while a group calling itself 1775 Sec falsely claimed to have breached it — a hoax that briefly stoked panic about user data.

Security Incidents & Data BreachesReliability & Data Loss
Read documentation
2 sources
MediumUsers in mainland China

Blocked behind the Great Firewall: Dropbox in China since 2014

China's Great Firewall has blocked Dropbox since 2014 — at one point cutting users off from their own files overnight without warning — leaving the service reachable in the country only via VPNs that are themselves restricted.

Product Changes & User BacklashGovernment Access & Surveillance
Read documentation

Q-CERT researchers found that because Dropbox did not verify email addresses at signup, an attacker who already had a victim's password could register a near-duplicate email, enable 2FA on it, and use the resulting emergency code to switch off the real account's two-step verification.

Security Incidents & Data Breaches
Read documentation

At USENIX WOOT 2013, Dhiru Kholia and Przemyslaw Wegrzyn unpacked and decompiled Dropbox's obfuscated-Python desktop client, demonstrated SSL interception via code injection, and described a way to hijack accounts and bypass two-factor authentication.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

At Black Hat Europe 2013, a researcher demonstrated 'DropSmack,' a technique that abused Dropbox sync to slip malware past corporate firewalls and quietly exfiltrate company files.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

The 2001 USA PATRIOT Act expanded US government access to records held by domestic companies and became the original reason foreign organizations distrusted storing data with US cloud providers — a concern that still attaches to Dropbox today.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Under the 1986 Stored Communications Act, US law enforcement can obtain a Dropbox user's basic subscriber records with a subpoena, account usage records with a court order, and the actual contents of their files with a search warrant — a tiered framework Dropbox publishes in its own guidelines.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
2 sources
LowUsers in sanctioned regions (Crimea, North Korea, Syria, others)

Switched off by sanctions: no Dropbox in Crimea, North Korea, and Syria

To comply with US trade sanctions and embargoes, Dropbox does not provide service in regions such as Crimea, North Korea, and Syria — meaning users there can be cut off from their existing files by their provider's home-country law.

Government Access & SurveillanceAccount Lockouts & Support Failures
Read documentation

Because gag orders bar providers from confirming secret national-security demands, some companies post a 'warrant canary' — a standing statement that disappears if such a demand arrives. Dropbox relies on banded transparency reporting rather than a canary, leaving the most sensitive demands invisible to users.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

As thousands of intercepted Snapchat photos leaked in the so-called 'Snappening,' early reports tied Dropbox to the incident — but Dropbox flatly denied any involvement, and the actual leaks came from third-party apps and unrelated breaches, not Dropbox's systems.

Security Incidents & Data Breaches
Read documentation

Days after Dropbox disclosed the June 2011 bug that briefly let anyone sign into any account with any password, a plaintiff filed a class action alleging privacy and consumer-protection violations; the case was terminated within four months.

Security Incidents & Data BreachesLegal Actions & Lawsuits
Read documentation