Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2022 phishing breach: 130 internal GitHub repositories stolen

November 2022

HighStatus: Resolved 130 internal GitHub repositories; a few thousand employee, customer, sales-lead, and vendor names and email addresses affectedProduct: Internal source code (GitHub)Year: 2022

A phishing campaign impersonating the CI provider CircleCI tricked Dropbox employees into handing over credentials and 2FA codes, letting attackers copy 130 of Dropbox's private source-code repositories.

What happened

In October 2022 Dropbox employees received phishing emails impersonating CircleCI, a code integration and delivery platform Dropbox used; a similar campaign against GitHub accounts had been publicly detailed by GitHub the month before. Dropbox later wrote: 'On October 14, 2022, GitHub alerted us to some suspicious behavior that began the previous day. Upon further investigation, we found that a threat actor—also pretending to be CircleCI—accessed one of our GitHub accounts, too.'

Dropbox described the mechanism directly: 'These legitimate-looking emails directed employees to visit a fake CircleCI login page, enter their GitHub username and password, and then use their hardware authentication key to pass a One Time Password (OTP) to the malicious site. This eventually succeeded, giving the threat actor access to one of our GitHub organizations where they proceeded to copy 130 of our code repositories.'

Dropbox said the stolen repositories 'included our own copies of third-party libraries slightly modified for use by Dropbox, internal prototypes, and some tools and configuration files used by the security team,' and did not include code for its 'core apps or infrastructure.' On the customer-data question, it was specific: 'At no point did this threat actor have access to the contents of anyone's Dropbox account, their password, or their payment information. To date, our investigation has found that the code accessed by this threat actor contained some credentials—primarily, API keys—used by Dropbox developers. The code and the data around it also included a few thousand names and email addresses belonging to Dropbox employees, current and past customers, sales leads, and vendors (for context, Dropbox has more than 700 million registered users).'

Impact

The breach demonstrated that even 2FA-protected accounts can fall to real-time phishing, and it exposed internal code, developer secrets, and a few thousand names and email addresses of employees, customers, sales leads, and vendors — though not account contents, passwords, or payment information. It prompted Dropbox to accelerate a move to phishing-resistant, hardware-based WebAuthn/FIDO2 authentication across the organization, and became a frequently cited example of CI/CD-targeted supply-chain phishing.

Dropbox's Response / Official Position

Dropbox disclosed the incident on 1 November 2022 in a post by its security team, 'How we handled a recent phishing incident that targeted Dropbox,' stating that 'no one's content, passwords, or payment information was accessed,' that its core apps and infrastructure were unaffected, and that 'one way we hope to prevent a similar incident from occurring is by accelerating our adoption of WebAuthn' — soon securing its whole environment with hardware tokens or biometric factors.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
5 sources
HighHundreds of thousands (estimated)

Guiffre v. Dropbox: the class action over the 2024 Dropbox Sign breach

Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.

Security Incidents & Data BreachesLegal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation