Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The January 2014 outage: hours of downtime and a fake 'hack' claim

January 2014

MediumStatus: ResolvedProduct: Core syncYear: 2014

On 10–11 January 2014 Dropbox went dark for roughly two hours after an internal maintenance error, while a group calling itself 1775 Sec falsely claimed to have breached it — a hoax that briefly stoked panic about user data.

What happened

On the evening of 10 January 2014 (around 6 p.m. PST) Dropbox suffered a service outage that left users unable to reach the website and sync for roughly two hours, with knock-on disruption continuing for some into the next day. Dropbox attributed the outage to an internal maintenance operation that went wrong: a routine process intended for one set of servers was applied to active production machines, taking the service down.

While the service was down, a group calling itself 1775 Sec announced on social media that it had 'compromised the Dropbox database,' posted purported user data, and framed the action as a tribute to internet activist Aaron Swartz on the anniversary of his death. The claim spread quickly before Dropbox refuted it. The company's engineering leadership stated plainly that users' files were always safe and that no hacking or DDoS attack was involved. The group itself subsequently admitted the breach claim was fabricated — a stunt partly designed to expose how readily the claim would be reported as fact.

Impact

The outage itself was a reliability failure caused by Dropbox's own maintenance process, underscoring how a single configuration mistake can take an entire cloud service offline for millions at once. The accompanying hoax added a second dimension of harm: even a fake breach claim can trigger real anxiety, password changes, and reputational damage for a custodian of private files — and it highlighted how thin the public's ability is to distinguish a genuine compromise from a fabricated one during a live outage.

Dropbox's Response / Official Position

Dropbox said the outage was caused during internal maintenance, not by any attack, and assured users their files were safe. Its VP of Engineering publicly stated that no hacking or DDoS was involved and that the service was restored after the maintenance error was corrected. Dropbox later published an engineering post-mortem describing how the faulty maintenance operation took the service down and the steps taken to prevent a repeat.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's own status page logged eleven separate incidents between January and September 2026 — mostly brief, but including a roughly 93-hour shared-content-download degradation in June and an 11-hour, 46-minute Dropbox Protect failure in August.

Reliability & Data LossCurrent / Ongoing Issues (2024–2026)
Read documentation