Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Winding down Dropbox Passwords: a password manager killed in 2025

Announced 2025 (fully discontinued 28 October 2025)

MediumStatus: HistoricalProduct: Dropbox PasswordsYear: 2025

Dropbox shut down Dropbox Passwords, the password manager it had launched in 2020, in a phased 2025 wind-down ending 28 October 2025 — after which all stored credentials and payment cards were permanently deleted from its servers.

What happened

Dropbox Passwords launched in 2020 as a built-in password manager: it stored logins and payment cards, offered autofill across devices, and added dark-web monitoring. Dropbox promoted it as a reason to stay inside the Dropbox ecosystem, and bundled it into paid plans.

In 2025 Dropbox announced it was discontinuing the product, telling users only that it was focusing 'on enhancing other features in our core product.' The shutdown ran in phases: on 28 August 2025 the service became read-only and autofill stopped; on 11 September 2025 the mobile app stopped working; and on 28 October 2025 the product was fully discontinued, after which all stored credentials and payment data were permanently deleted from Dropbox's servers and dark-web monitoring ceased.

Users had to export their entire vault to a CSV file and migrate to a rival manager before the cutoff or lose the data outright. For a tool whose entire purpose was holding people's most sensitive secrets, the burden of a clean, secure migration — and the hard deletion deadline — fell entirely on users.

Impact

Killing a password manager is a uniquely high-stakes form of feature removal: the product holds the keys to a person's entire online life, and a missed export deadline meant permanent loss of stored credentials. The shutdown reinforced the long-running pattern of Dropbox abandoning add-on consumer features and deepened distrust about building any workflow on a Dropbox-owned tool, pushing users toward dedicated managers such as 1Password and Bitwarden.

Dropbox's Response / Official Position

Dropbox documented the wind-down in a help-center notice, stating the Passwords app would be discontinued on 28 October 2025 as part of refocusing on its core product, and instructed users to export their logins and payment cards as a CSV before that date. It did not offer a successor product.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation