Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Man-in-the-Cloud: stealing Dropbox sync tokens to hijack accounts without a password

August 2015

HighStatus: HistoricalProduct: Desktop clientYear: 2015

At Black Hat USA 2015, Imperva researchers showed that stealing a single synchronization token let an attacker take over a Dropbox account and read its files indefinitely — and that, in Dropbox's case, changing the password did not revoke the stolen token.

What happened

In its August 2015 Hacker Intelligence Initiative report 'Man in the Cloud (MITC) Attacks,' Imperva's Application Defense Center demonstrated how popular file-sync services including Dropbox, Google Drive, Box and OneDrive could be quietly converted into attack tools. Instead of stealing a password, the attacker steals the synchronization token that the desktop client stores locally after the first login — a token that can be lifted with ordinary, low-suspicion code and replayed from the attacker's own machine to silently sync the victim's files.

Imperva's proof-of-concept tool, 'Switcher,' social-engineered a victim into installing the attacker's token, causing the victim's machine to hand a copy of its legitimate token back to the attacker. The report singled out a Dropbox-specific weakness: the synchronization token (the host_id value) was not changed or revoked when the user changed their password — it changed only when the device was explicitly unlinked. Imperva noted that revoking a stolen token was 'tricky' on Dropbox, making persistent, password-independent access especially hard to shut down.

Impact

MITC reframed cloud-storage risk around tokens rather than passwords, showing that two-factor authentication and password resets — the usual responses to account compromise — do nothing against an attacker holding a valid sync token. It pushed enterprises toward monitoring for anomalous token use and CASB controls, and underscored that local credential storage in sync clients is a high-value target. The research compounded earlier criticism (Derek Newton, 2011) that Dropbox's device tokens were dangerously durable.

Dropbox's Response / Official Position

Imperva said it disclosed the findings to the affected vendors; the report frames token theft as an industry-wide design issue rather than a single bug. Dropbox has continued to rely on per-device linking that users can revoke from the web account-security page, and points users to its linked-devices and session controls.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation