Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2014 shared-link leak: 'private' documents exposed via referer headers and search

May 2014

HighStatus: ResolvedProduct: Shared linksYear: 2014

Researchers found that Dropbox's shared links to supposedly private documents could leak to third parties — exposed through browser referer headers and, in some cases, surfacing in Google search results — revealing tax returns, bank records, and business plans.

What happened

In May 2014 the security firm Intralinks reported that 'private' Dropbox shared links were leaking to outside parties. Routine analysis of Google AdWords and Analytics data had surfaced fully clickable URLs leading to sensitive documents — tax returns, bank records, mortgage applications, blueprints, and business plans — that their owners believed were accessible only to people they had given the link to.

The leak worked two ways. First, when a shared document contained a hyperlink to an external site, clicking that link passed the secret Dropbox URL to the third-party site in the HTTP referer header; whoever ran that site could then open the 'private' document. Second, if a user pasted a shared link into a search box instead of the address bar — a common mistake — the URL could end up indexed and appear in search results. In both cases the underlying weakness was that Dropbox's shared links functioned as 'security through obscurity': knowing the URL was enough to open the file.

Dropbox confirmed and patched the issue, disabling access to previously shared links to documents that could be affected and fixing newly created links, while saying it was unaware of any actual abuse.

Impact

The incident punctured the assumption that a Dropbox 'shared link' was meaningfully private and showed that a convenience feature could expose deeply sensitive personal and corporate documents to strangers. It forced Dropbox and the similarly affected Box to rethink shared-link security, accelerated the move toward link passwords and expirations, and became a standard cautionary example of how referer-header leakage and unguessable-URL designs fail in practice.

Dropbox's Response / Official Position

Dropbox published a blog post, 'Web vulnerability affecting shared links,' acknowledging the flaw, stating it had patched all newly created shared links and disabled access to previously shared links to potentially affected documents, and that it was working to restore links that were not susceptible. It said it had no indication the vulnerability had been abused and later added shared-link controls such as passwords and expirations on paid plans.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation