Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2016 mass password reset: forcing millions to re-secure pre-2012 accounts

August 2016

HighStatus: Resolved all pre-mid-2012 users who had not changed their password affectedProduct: Core syncYear: 2016

When the full 2012 credential dump resurfaced in 2016, Dropbox forced a password reset on every user who had signed up before mid-2012 and never changed their password — a sweeping operational response that, for many, was the first sign anything was wrong.

What happened

In late August 2016 Dropbox began emailing users and silently expiring passwords for anyone who had created an account before mid-2012 and had not changed it since. The trigger was the emergence of the full database of roughly 68 million credentials stolen in the 2012 incident — data whose true scale Dropbox had not disclosed at the time. Rather than wait to see whether accounts were being abused, Dropbox invalidated the old passwords and required affected users to set new ones on next login.

The company described the reset as 'purely a preventative measure' and stressed it had no evidence any accounts had been improperly accessed. But the rollout meant many long-dormant users were abruptly locked out and prompted to reset, and it publicly reframed the 2012 event — originally characterized as exposing only email addresses — as a credential breach large enough to warrant mass intervention four years later.

Impact

The reset is a case study in delayed-disclosure fallout: the operational scramble in 2016 was the visible consequence of an under-described 2012 breach, and it forced millions to act on a four-year-old exposure. It accelerated Dropbox's push on two-step verification and password-strength checks, but also fueled criticism that users learned the real risk far too late.

Dropbox's Response / Official Position

Dropbox posted 'Resetting passwords to keep your files safe,' explaining that it was completing a password reset for users who had not updated since mid-2012, calling it a preventative step, noting the stolen passwords were hashed and salted, and urging two-step verification.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
2 sources
Medium1,180+ documented BBB complainants (3-year window)

Over 1,180 BBB complaints: the paper trail of Dropbox's billing and support grievances

The Better Business Bureau has logged more than 1,180 complaints against Dropbox over three years, dominated by surprise auto-renewal charges, denied refunds, and support tickets that vanish without resolution.

Pricing & Business PracticesAccount Lockouts & Support Failures
Read documentation