Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2011 FTC complaint: a researcher accuses Dropbox of misleading users about encryption

May 2011

HighStatus: HistoricalProduct: Core syncYear: 2011

Security researcher Christopher Soghoian filed a complaint with the U.S. Federal Trade Commission alleging that Dropbox made deceptive claims about its encryption, because Dropbox employees could in fact access users' files.

What happened

On 11 May 2011, security researcher Christopher Soghoian — a former technologist in the FTC's own Division of Privacy and Identity Protection — submitted a complaint to the Federal Trade Commission asking it to investigate Dropbox. The complaint alleged that Dropbox had engaged in deceptive trade practices by telling users their files were encrypted and inaccessible to Dropbox employees, when in reality Dropbox held the encryption keys and its staff could access unencrypted user data.

The complaint pointed to Dropbox marketing language stating that files were inaccessible without the user's password and that employees were not able to view stored files. Shortly before the complaint, Dropbox had quietly revised its security and terms-of-service language to clarify that it could decrypt files when legally compelled — a change critics said amounted to an admission that the earlier representations were misleading. The complaint asked the FTC to compel Dropbox to correct its statements and to compensate affected users.

The FTC complaint was a request for the agency to act rather than a court case, and there is no public record that the FTC brought a formal enforcement action against Dropbox over these claims. The episode nonetheless became a foundational moment in the long-running scrutiny of Dropbox's security representations.

Impact

The complaint reframed a technical critique as a potential consumer-protection violation and put Dropbox's marketing language under regulatory and public scrutiny. It foreshadowed the June 2011 authentication bug weeks later, which appeared to validate the core concern that Dropbox could access user files and represented a single point of failure. The matter durably shaped the narrative that Dropbox's server-side encryption model was a trust liability, and it fueled demand for 'zero-knowledge' alternatives.

Dropbox's Response / Official Position

Dropbox said it believed the complaint was 'without merit' and that the issues had been addressed in an April 2011 blog post, emphasizing that millions of people relied on the service and that it worked hard to keep data safe, secure and private. It had already updated its terms and security descriptions to state that it could access and decrypt files when required by law.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation