The 2014 'Snappening': Dropbox wrongly named, then cleared
October 2014
As thousands of intercepted Snapchat photos leaked in the so-called 'Snappening,' early reports tied Dropbox to the incident — but Dropbox flatly denied any involvement, and the actual leaks came from third-party apps and unrelated breaches, not Dropbox's systems.
What happened
In October 2014 a trove of images sent via Snapchat leaked online in an episode dubbed the 'Snappening.' The breach was traced to Snapsaved.com, an unofficial third-party app that secretly saved Snapchat photos against Snapchat's terms. Amid the same news cycle, separate posts of Dropbox usernames and passwords on sites such as Pastebin.com led some early coverage to associate Dropbox with the leaks; Advisen — 'Third-party apps expose Snapchat photos, Dropbox user info' reported that 'users of several sites such as Pastebin.com posted hundreds of samples of usernames and passwords from Dropbox,' and that 'the poster said he has more and will post them for donations of Bitcoin.'
NPR's report — headlined 'Snapchat And Dropbox Breaches Are Really Third-Party-App Breaches' — made the underlying point directly: 'What can get lost in a flurry of news about Dropbox and Snapchat getting hacked is that the companies themselves deny they were hacked at all. They're not lying. Technically speaking, Dropbox's servers did not get breached. Snapchat's didn't either. Photos and log-in credentials apparently leaked from third-party sites or apps that piggyback on these services.' NPR added a Dropbox clarification appended after initial publication: 'A Dropbox spokesperson says the stolen logins were a result of users who use the same passwords and sign-in credentials across several sites — not a breach of any specific third-party apps.'
Snapchat issued its own denial, carried by Advisen: 'We can confirm that Snapchat's servers were never breached and were not the source of these leaks. Snapchatters were victimized by their use of third-party apps to send and receive Snaps, a practice that we expressly prohibit in our Terms of Use precisely because they compromise our users' security.' Snapsaved.com itself admitted the breach on its end: 'As soon as we discovered the breach in our systems, we immediately deleted the entire website and the database associated with it.' As reporting clarified, the Snapchat photo leak and the Dropbox credential-stuffing claims were distinct events — one a genuine third-party-app compromise, the other reused passwords tried against Dropbox logins — neither of which was a breach of Dropbox's or Snapchat's own systems.
Impact
The episode is a cautionary example of breach misattribution: Dropbox's brand was swept into a sensational story it had no part in, and the correction never travels as fast as the accusation. It reinforced two real lessons — that third-party apps piggybacking on a service can expose users while the named service stays intact, and that credential lists circulated as a fresh 'hack' are often recycled from unrelated breaches and password reuse.