Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Fake Dropbox logins: recurring campaigns impersonating the brand to steal credentials

2022–2026

MediumStatus: OngoingProduct: Core syncYear: 2026

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

What happened

Separate from campaigns that host content on Dropbox, a long-running class of attacks simply impersonates Dropbox. Cofense documented a prolific operation in 2022 in which booby-trapped links led through Dropbox-hosted files to external credential-harvesting pages, with stolen logins exfiltrated to PHP panels on compromised domains. The pattern persisted: in early 2026 Forcepoint's X-Labs detailed a procurement-themed campaign that mailed PDF attachments, staged an intermediate document on cloud storage (Vercel Blob), then dropped victims onto a fake Dropbox login page at an attacker domain that captured email addresses, passwords, IPs and geolocation and shipped them to a Telegram bot.

These campaigns do not breach Dropbox; they weaponize the trust users place in the brand. Because the fake pages mirror Dropbox's real interface and arrive via legitimate-looking attachments, they evade naive defenses and rely on the victim not checking the destination URL.

Impact

Persistent brand-impersonation phishing means Dropbox's name is repeatedly used as bait to compromise both Dropbox accounts and unrelated work credentials, a reputational and ecosystem harm that Dropbox cannot fully control. It keeps Dropbox among the most-imitated brands in phishing telemetry and reinforces why password-only logins and credential reuse remain the dominant route to account takeover.

Dropbox's Response / Official Position

Dropbox publishes guidance on spotting fake Dropbox emails and login pages, urges users to verify URLs and enable two-step verification, and operates an abuse/phishing reporting channel; specific campaigns are typically first exposed by security vendors such as Cofense and Forcepoint.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
2 sources
Medium1,180+ documented BBB complainants (3-year window)

Over 1,180 BBB complaints: the paper trail of Dropbox's billing and support grievances

The Better Business Bureau has logged more than 1,180 complaints against Dropbox over three years, dominated by surprise auto-renewal charges, denied refunds, and support tickets that vanish without resolution.

Pricing & Business PracticesAccount Lockouts & Support Failures
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation