Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2014 'Snappening': Dropbox wrongly named, then cleared

October 2014

LowStatus: DisputedProduct: Core syncYear: 2014

As thousands of intercepted Snapchat photos leaked in the so-called 'Snappening,' early reports tied Dropbox to the incident — but Dropbox flatly denied any involvement, and the actual leaks came from third-party apps and unrelated breaches, not Dropbox's systems.

What happened

In October 2014 a trove of images sent via Snapchat leaked online in an episode dubbed the 'Snappening.' The breach was traced to Snapsaved.com, an unofficial third-party app that secretly saved Snapchat photos against Snapchat's terms. Amid the same news cycle, separate posts of Dropbox usernames and passwords on sites such as Pastebin.com led some early coverage to associate Dropbox with the leaks; Advisen — 'Third-party apps expose Snapchat photos, Dropbox user info' reported that 'users of several sites such as Pastebin.com posted hundreds of samples of usernames and passwords from Dropbox,' and that 'the poster said he has more and will post them for donations of Bitcoin.'

NPR's report — headlined 'Snapchat And Dropbox Breaches Are Really Third-Party-App Breaches' — made the underlying point directly: 'What can get lost in a flurry of news about Dropbox and Snapchat getting hacked is that the companies themselves deny they were hacked at all. They're not lying. Technically speaking, Dropbox's servers did not get breached. Snapchat's didn't either. Photos and log-in credentials apparently leaked from third-party sites or apps that piggyback on these services.' NPR added a Dropbox clarification appended after initial publication: 'A Dropbox spokesperson says the stolen logins were a result of users who use the same passwords and sign-in credentials across several sites — not a breach of any specific third-party apps.'

Snapchat issued its own denial, carried by Advisen: 'We can confirm that Snapchat's servers were never breached and were not the source of these leaks. Snapchatters were victimized by their use of third-party apps to send and receive Snaps, a practice that we expressly prohibit in our Terms of Use precisely because they compromise our users' security.' Snapsaved.com itself admitted the breach on its end: 'As soon as we discovered the breach in our systems, we immediately deleted the entire website and the database associated with it.' As reporting clarified, the Snapchat photo leak and the Dropbox credential-stuffing claims were distinct events — one a genuine third-party-app compromise, the other reused passwords tried against Dropbox logins — neither of which was a breach of Dropbox's or Snapchat's own systems.

Impact

The episode is a cautionary example of breach misattribution: Dropbox's brand was swept into a sensational story it had no part in, and the correction never travels as fast as the accusation. It reinforced two real lessons — that third-party apps piggybacking on a service can expose users while the named service stays intact, and that credential lists circulated as a fresh 'hack' are often recycled from unrelated breaches and password reuse.

Dropbox's Response / Official Position

Dropbox's own blog post, quoted by Advisen, said flatly: 'Recent news articles claiming that Dropbox was hacked aren't true. Your stuff is safe.' It explained: 'The usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox. Attackers then used these stolen credentials to try to log in to sites across the internet, including Dropbox. We have measures in place to detect suspicious login activity and we automatically reset passwords when it happens.' NPR reported that in a separate blog post 'Dropbox told its users that their data were safe,' urging them 'not to reuse passwords across services' and recommending they 'enable two-step verification.'

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
5 sources
HighHundreds of thousands (estimated)

Guiffre v. Dropbox: the class action over the 2024 Dropbox Sign breach

Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.

Security Incidents & Data BreachesLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation