Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

Category

Privacy & Encryption Concerns

Server-side keys, government access, shared-link leaks, and the gap between Dropbox's privacy promises and its design.

About this category

For most of its history Dropbox has held the encryption keys to its users' files, meaning it can technically read, scan, hand over, or lose access to that data — a design repeatedly criticized by security researchers and privacy advocates. This section covers the recurring tensions: the 2011 controversy when Dropbox quietly amended its terms to clarify it could decrypt files to comply with law enforcement, contradicting earlier marketing; the 2014 backlash after Edward Snowden called Dropbox "hostile to privacy" and the company appointed former Secretary of State Condoleezza Rice to its board, prompting a 'Drop Dropbox' campaign; the 2014 shared-link flaw that exposed private documents to third parties and search engines; and ongoing concerns over data scanning, retention, and how user content is used — including the 2024 dispute over whether files were being fed to AI partners. The focus is the distance between what Dropbox tells users about their privacy and how the system actually works.

Documented issues(55)

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

Dash connects to Google Workspace, Microsoft 365, Slack, Notion and more, and routes queries through large language models — leaving users to trust Dropbox's contractual assurances that connected and indexed data is not used to train third-party AI models.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Developer, API & Platform
Read documentation
2 sources
Medium

Discontinuing Dropbox Vault: the PIN-protected folder turned ordinary

Dropbox discontinued Dropbox Vault, the PIN-protected folder for sensitive files, on 4 March 2025 — automatically converting every Vault into an ordinary, un-PIN'd Dropbox folder.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Through 2025 Dropbox pushed Dash to general availability with self-serve sign-up and no IT required, marketing it as an AI assistant that indexes content across all of a user's connected apps — a model that, by design, reaches far beyond the files stored in Dropbox.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation
2 sources
Medium~68 million (2012 credentials, re-aggregated)

2024: Dropbox's 2012 credentials resurface in the 'Mother of All Breaches'

In January 2024 a 26-billion-record compilation dubbed the 'Mother of All Breaches' surfaced online — and the 68 million credentials stolen from Dropbox in 2012 were among the datasets bundled into it.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

A 2024 Proton analysis found Dropbox's privacy policy permits extensive data sharing with third parties — including Google, Amazon, OpenAI, Kissmetrics, and Stripe — and lets Dropbox volunteer user data to authorities in the vaguely defined 'public interest.'

Privacy & Encryption Concerns
Read documentation

The Dropbox Dash Chrome extension requests permission to 'read and change all your data on all websites' and imports up to 90 days of browsing history — URLs, page titles, and page contents — to power its AI search.

Privacy & Encryption Concerns
Read documentation

Dropbox runs industry hash-matching (PhotoDNA, NCMEC and IWF hash lists) and an unhashed-content classifier across files added to or shared on the service, reporting matches to NCMEC — a legitimate child-safety system that is also, by design, a server-side scan of users' private content.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox uses cookies and machine learning to profile how engaged each user is — analyzing connected devices, storage used, file content, and sharing actions — to market premium services, with regional differences in what is on by default.

Privacy & Encryption Concerns
Read documentation

If a user enables two-factor authentication and later loses their authenticator app, backup phone and emergency backup code, Dropbox support has told users it has no process to restore access — and the account, with all its files, is effectively lost.

Privacy & Encryption ConcernsAccount Lockouts & Support Failures
Read documentation

Dropbox's own engineering writing describes an analytics pipeline that logs fine-grained user-behavior events in its mobile apps — button clicks, navigation across screens, sign-in failures, upload timing — to study 'complex user scenarios.'

Privacy & Encryption Concerns
Read documentation

Users discovered a 'third-party AI' setting that was switched on by default for most of the world, fueling fears that Dropbox was quietly feeding personal files to OpenAI. Dropbox said no data was passively sent and that files were not used to train models.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation
3 sources
MediumBoxcryptor users (free accounts ended 31 Jan 2023)

2022: Dropbox buys Boxcryptor's assets — then winds the service down for its users

Dropbox acquired key assets of Boxcryptor, the zero-knowledge encryption tool many used to protect files on Dropbox — and Boxcryptor stopped taking new users and cancelled free accounts, pushing existing users to migrate.

Privacy & Encryption ConcernsProduct Changes & User Backlash
Read documentation

Many third-party integrations request broad, full-Dropbox access rather than scoped, folder-limited permissions — so a single connected app, if compromised, can expose everything in an account.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsDeveloper, API & Platform
Read documentation

ESET and Avast documented the Worok espionage group's 'DropBoxControl' backdoor, which abused the Dropbox API as its entire command-and-control channel — reading commands from, and uploading stolen data to, ordinary files in a Dropbox account.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Dropbox's API lets connected third-party apps request 'Full Dropbox' access to a user's entire account, and broad OAuth scopes mean an app users link for one task can often read far more than they expect.

Privacy & Encryption ConcernsDeveloper, API & Platform
Read documentation
2 sources
Medium~19.3% of warrant-affected users in H1 2021 (indefinite gag)

Indefinite gag orders: the users Dropbox is barred from ever warning

Dropbox's own Transparency Report shows that a large share of the search warrants it receives arrive with indefinite non-disclosure orders, leaving the company unable to ever notify those users that the government took their data.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Italy's competition and consumer authority opened proceedings against Dropbox in 2020 over its cloud-storage terms; in 2021 it closed one case after Dropbox committed to clearer disclosures and, in a second, found several contract clauses unfair and ordered their removal — in both cases without a fine on Dropbox.

Privacy & Encryption ConcernsLegal Actions & LawsuitsPricing & Business Practices
Read documentation

The DropSmack proof-of-concept warned that synced Dropbox folders could be a covert C2 and exfiltration channel; multiple real malware families — including BoxCaon, Crutch and tooling used by Kimsuky — went on to abuse Dropbox folders and the Dropbox API exactly that way.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

European courts and regulators treat data held by US providers as inherently reachable by US surveillance under FISA Section 702 and the CLOUD Act — a structural concern that applies to any US-controlled cloud service, including Dropbox, regardless of where servers sit.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox launched a zero-knowledge password manager in 2020, but reviewers and privacy advocates questioned trusting a vault to a company that — for its core product — holds the encryption keys and has a documented history of breaches.

Privacy & Encryption Concerns
Read documentation

When the EU's top court struck down the EU–US Privacy Shield in 2020, Dropbox — which had self-certified under the framework — was among the US cloud services left exposed to European data-protection regulators questioning whether personal data could lawfully be transferred to the United States.

Privacy & Encryption ConcernsLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation
3 sources
MediumEU/EEA organizations and users

Schrems II: why EU users' files on Dropbox sit under a legal cloud

The EU's 2020 Schrems II ruling struck down the Privacy Shield framework over US surveillance, leaving EU organizations that store data with US providers like Dropbox needing extra safeguards — and unable to fully escape US legal reach.

Privacy & Encryption ConcernsLegal Actions & LawsuitsGovernment Access & Surveillance
Read documentation

Apple's App Store privacy 'nutrition labels,' introduced in December 2020, require apps to disclose their data collection — and the Dropbox app's label lists a broad range of data linked to the user's identity, from contact info and identifiers to usage data and diagnostics.

Privacy & Encryption Concerns
Read documentation

Anyone viewing a publicly shared Dropbox Paper document could see the full names and email addresses of every signed-in Dropbox user who had ever opened it — turning a collaboration feature into a personal-data harvesting tool.

Privacy & Encryption Concerns
Read documentation

Dropbox's transparency reporting centers on US legal process, but as a global service it also faces foreign-government and cross-border demands — an area where its disclosures are thinner and the CLOUD Act blurs jurisdictional lines.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
3 sources
Medium~16,000 scientists (reporting referenced data tied to ~400,000 users)

Sharing 16,000 scientists' folder data with researchers — without telling them

Dropbox gave Northwestern University researchers project-folder metadata covering some 16,000 scientists to study collaboration patterns. Users were never told their activity would be used for research, and academics warned the 'anonymized' data could re-identify individuals.

Privacy & Encryption ConcernsProduct Changes & User Backlash
Read documentation

The 2018 CLOUD Act amended US law so that a US-based provider like Dropbox can be compelled to produce a user's data regardless of which country the data is physically stored in — meaning a US warrant can reach an overseas user's files.

Privacy & Encryption ConcernsLegal Actions & LawsuitsGovernment Access & Surveillance
Read documentation

In January 2017 files and folders that users had deleted — in some cases as far back as 2009 — suddenly reappeared in their accounts, revealing that 'deleted' data had been retained on Dropbox's servers far longer than its own policy promised.

Privacy & Encryption ConcernsReliability & Data Loss
Read documentation

Researchers revealed that Dropbox's Mac client used a user's admin password to directly edit macOS's protected TCC.db permissions database, inserting itself into the Accessibility list — a privacy/trust list that grants near-total control over the machine — without a clear, informed prompt.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsReliability & Data Loss
Read documentation

Because Dropbox holds the keys to decrypt users' files, a valid legal order doesn't just get a government encrypted data it can't read — it gets readable file content. The design choice is what makes lawful compulsion effective.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox runs every uploaded image and video through hash-matching systems such as Microsoft's PhotoDNA to detect known child sexual abuse material — automated scanning of users' private files that the company initially refused to explain.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

At Black Hat USA 2015, Imperva researchers showed that stealing a single synchronization token let an attacker take over a Dropbox account and read its files indefinitely — and that, in Dropbox's case, changing the password did not revoke the stolen token.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Responding to criticism of Dropbox's lack of zero-knowledge encryption, CEO Drew Houston framed the fact that Dropbox can access users' files as a deliberate 'trade-off between usability/convenience and security.'

Privacy & Encryption Concerns
Read documentation

Dropbox's April 2014 appointment of former Secretary of State Condoleezza Rice — a defender of warrantless wiretapping — to its board triggered the grassroots 'Drop Dropbox' campaign, and months later Edward Snowden publicly branded the service 'hostile to privacy.'

Privacy & Encryption ConcernsProduct Changes & User Backlash
Read documentation

A viral 2014 incident revealed that Dropbox compares the cryptographic hashes of files users try to share against a blacklist of DMCA-flagged content and blocks matches — surprising users who assumed their files were entirely private.

Privacy & Encryption ConcernsProduct Changes & User Backlash
Read documentation

After the 2013 PRISM disclosures named major US tech firms, Dropbox spent the following years documenting — through its own reports and advocacy — that it sits inside the same surveillance ecosystem: subject to NSLs, FISA orders and rising law-enforcement demands, with only banded, gagged disclosure permitted.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Because gag orders bar providers from confirming secret national-security demands, some companies post a 'warrant canary' — a standing statement that disappears if such a demand arrives. Dropbox relies on banded transparency reporting rather than a canary, leaving the most sensitive demands invisible to users.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Researchers found that Dropbox's shared links to supposedly private documents could leak to third parties — exposed through browser referer headers and, in some cases, surfacing in Google search results — revealing tax returns, bank records, and business plans.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

At Black Hat Europe 2013, a researcher demonstrated 'DropSmack,' a technique that abused Dropbox sync to slip malware past corporate firewalls and quietly exfiltrate company files.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

At USENIX WOOT 2013, Dhiru Kholia and Przemyslaw Wegrzyn unpacked and decompiled Dropbox's obfuscated-Python desktop client, demonstrated SSL interception via code injection, and described a way to hijack accounts and bypass two-factor authentication.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Among the classified NSA PRISM documents leaked by Edward Snowden, Dropbox appeared as a provider the surveillance program planned to add, listed as 'coming soon' — placing the company squarely inside the post-Snowden surveillance debate.

Privacy & Encryption Concerns
Read documentation
3 sources
High0–249 national-security requests reported for 2013

National Security Letters and FISA orders: demands Dropbox can barely acknowledge

Dropbox is subject to National Security Letters and FISA orders that arrive with gag provisions barring it from disclosing even that it received them; the most it can publish is a band such as '0–249' national-security requests.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox has published a biannual Transparency Report since 2012, and its own figures document a steady, long-run climb in government and law-enforcement demands for user data — including reporting periods where US legal-process requests jumped by roughly a third.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
4 sources
Critical68,648,009, per Troy Hunt's independent count (Dropbox described it as 'roughly 68 million')

The 2012 breach: 68 million user credentials stolen via a reused password

An attacker used a Dropbox employee's reused password to steal a file containing roughly 68 million users' email addresses and hashed passwords — a theft whose full scale only became public in 2016.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Researcher Derek Newton showed that Dropbox's desktop client stored an unencrypted authentication token (host_id) in a local config.db file — copy that one value to another machine and you owned the victim's account, with no password and no notification.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

A July 2011 terms-of-service and privacy-policy update used broad licensing language that many users read as Dropbox asserting ownership-like rights over their files, forcing the company to publicly clarify and walk back the wording.

Privacy & Encryption ConcernsLegal Actions & Lawsuits
Read documentation

Dropbox splits files into blocks, hashes each with SHA-256, and stores only one copy of any block it already holds — a cost-saving design that researcher Christopher Soghoian warned could leak whether a given file already exists on Dropbox's servers.

Privacy & Encryption Concerns
Read documentation

Dropbox encrypts files at rest, but the encryption keys belong to Dropbox, not the user. This server-side model — chosen to enable deduplication, previews, and search — means the company can read user files, the root cause critics return to again and again.

Privacy & Encryption Concerns
Read documentation

Security researcher Christopher Soghoian filed a complaint with the U.S. Federal Trade Commission alleging that Dropbox made deceptive claims about its encryption, because Dropbox employees could in fact access users' files.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsLegal Actions & Lawsuits
Read documentation

Security researcher Christopher Soghoian filed an FTC complaint alleging Dropbox had told users their files were inaccessible even to Dropbox employees, while its actual architecture — and a quietly revised Terms of Service — made clear the company could decrypt and hand over files.

Privacy & Encryption ConcernsLegal Actions & Lawsuits
Read documentation
2 sources
Criticalfewer than a hundred, per Dropbox's final count (initially described as 'much less than 1 percent' of accounts that logged in during the window)

The 2011 authentication bug: any password unlocked any account

For nearly four hours on 19 June 2011, a code update left Dropbox accounts accessible with any password at all — anyone could sign in to any account by typing anything.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

The 2001 USA PATRIOT Act expanded US government access to records held by domestic companies and became the original reason foreign organizations distrusted storing data with US cloud providers — a concern that still attaches to Dropbox today.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Under the 1986 Stored Communications Act, US law enforcement can obtain a Dropbox user's basic subscriber records with a subpoena, account usage records with a court order, and the actual contents of their files with a search warrant — a tiered framework Dropbox publishes in its own guidelines.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation