Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2014 'Dropbox hack' that wasn't: leaked credentials and ransom

October 2014

MediumStatus: Disputed ~7 million claimed by the Pastebin poster; Dropbox said the passwords had already been expired affectedProduct: Core syncYear: 2014

Hackers claimed to have stolen nearly 7 million Dropbox logins, posted batches on Pastebin, and demanded Bitcoin — but the credentials came from other breached services, not Dropbox itself.

What happened

In October 2014 anonymous users posted hundreds of Dropbox username-and-password pairs to Pastebin and solicited Bitcoin donations to release more. TechCrunch reported at the time: 'After last week's Snapchat photo hack, it's cloud storage provider Dropbox's turn in the unsavory insecurity spotlight. An anonymous Pastebin user has claimed to have compromised almost seven million Dropbox account credentials (emails and passwords), posting the first 400 direct to Pastebin with a call for Bitcoin donations to leak more.'

Dropbox investigated and said its systems had not been breached. In a post titled 'Dropbox wasn't hacked,' it wrote: 'Recent news articles claiming that Dropbox was hacked aren't true. Your stuff is safe. The usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox. Attackers then used these stolen credentials to try to log in to sites across the internet, including Dropbox. We have measures in place to detect suspicious login activity and we automatically reset passwords when it happens.' When a second batch of credentials surfaced the next day, Dropbox added an update to the same post: 'A subsequent list of usernames and passwords has been posted online. We've checked and these are not associated with Dropbox accounts.'

TechCrunch's own reporting reached a similar conclusion, noting that the follow-up leaks 'do not appear to be genuine' and that the underlying cause looked like password reuse rather than any compromise of Dropbox's own systems: 'If it's a case of simple password cross-pollination (i.e. web users reusing the same login credentials) across multiple services then Dropbox's claim that its servers have not been hacked does technically stand up. However the end result — user accounts compromised — is the same.'

Impact

Even though Dropbox's own systems were not breached, the incident showed how the company's brand could be weaponized and how password reuse left its users exposed regardless of Dropbox's internal security. It became a recurring talking point in arguments for two-factor authentication and against single-factor cloud logins.

Dropbox's Response / Official Position

Dropbox published a post titled 'Dropbox wasn't hacked,' stating that 'the usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox,' urging users to enable two-step verification and avoid reusing passwords, and confirming in a follow-up update that a second leaked batch was 'not associated with Dropbox accounts.'

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
5 sources
HighHundreds of thousands (estimated)

Guiffre v. Dropbox: the class action over the 2024 Dropbox Sign breach

Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.

Security Incidents & Data BreachesLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation