Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2024 Dropbox Sign breach: e-signature data exposed

April–May 2024

CriticalStatus: OngoingProduct: Dropbox SignYear: 2024

An attacker compromised the production environment of Dropbox Sign (formerly HelloSign), exposing customer emails, usernames, phone numbers, hashed passwords, and authentication secrets including API keys, OAuth tokens, and MFA data.

What happened

On 24 April 2024 Dropbox discovered unauthorized access to the production systems of Dropbox Sign, its e-signature service formerly known as HelloSign. The company disclosed the breach on 1 May 2024, including in a filing with the U.S. Securities and Exchange Commission.

Dropbox said a threat actor had accessed a Dropbox Sign automated system configuration tool and used its elevated privileges to reach the customer database. Exposed data included account holders' emails, usernames, phone numbers, and hashed passwords, along with general account settings and authentication information such as API keys, OAuth tokens, and multi-factor authentication details. For people who had received or signed documents through Dropbox Sign without ever creating an account, email addresses and names were exposed. Dropbox said it found no evidence the attacker accessed the contents of users' documents or agreements, or their payment information.

Impact

The breach was the most serious Dropbox security incident in years and the first to clearly expose live customer authentication secrets at scale, forcing API key and OAuth token rotations across affected integrations. Coming after the 2022 GitHub breach, it renewed questions about Dropbox's segmentation and its custody of sensitive data — and it remains a live matter, with consumer litigation and regulatory attention following the disclosure.

Dropbox's Response / Official Position

Dropbox disclosed the incident via an 8-K filing and a Dropbox Sign blog post, reset passwords, logged users out of connected devices, rotated API keys and OAuth tokens, and emailed affected users with instructions. It said the breach was limited to the Dropbox Sign environment and did not affect other Dropbox products.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation