Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Class actions over the 2024 Dropbox Sign breach: negligence and delayed-notice claims

2024

HighStatus: OngoingProduct: Dropbox SignYear: 2024

After Dropbox disclosed the April 2024 Dropbox Sign breach, affected users filed proposed class actions in federal court alleging Dropbox negligently failed to protect their data and did not give prompt, adequate notice; the claims are allegations and the consolidated litigation followed in the Northern District of California.

What happened

Dropbox disclosed on 1 May 2024 that an attacker had accessed the production environment of Dropbox Sign (formerly HelloSign), exposing customer data including emails, usernames, phone numbers, hashed passwords, and authentication information such as API keys, OAuth tokens, and MFA details. (The breach mechanics are covered separately; this entry concerns the litigation that followed.)

In the weeks after the disclosure, affected users filed proposed class-action lawsuits in the U.S. District Court for the Northern District of California. Plaintiffs including a Florida resident and a California resident alleged that Dropbox failed to implement adequate and reasonable data-security measures, did not encrypt sensitive information, and did not provide prompt and accurate notice of the breach. The complaints asserted theories such as negligence and sought damages, attorneys' fees, and injunctive relief — including demands that Dropbox fund long-term credit monitoring and submit to annual security audits. The suits were subsequently consolidated into a single class action in the Northern District of California.

These filings are allegations; as of this writing there is no public record of a finding of liability against Dropbox or of a final approved settlement in the consolidated case. The matter remains a live, post-2024 legal exposure tied to the breach.

In 2025, U.S. District Judge Jeffrey S. White granted Dropbox's motion to compel arbitration, ruling that plaintiffs who completed a signature request through Dropbox Sign had been shown a hyperlink to Dropbox's terms of service and, by clicking 'I agree' to sign the document, had agreed to be bound by those terms, including the arbitration clause and class-action waiver. The plaintiffs sought reconsideration, arguing the consent was not meaningful, but the court denied the motion — a ruling reported on 15 May 2026 — leaving the order intact and sending the breach claims to individual arbitration rather than a consolidated class action.

Impact

The litigation translated the 2024 Dropbox Sign breach into direct legal and financial exposure and renewed questions about Dropbox's data-security practices and breach-notification timeline. Because Dropbox Sign handles e-signature workflows for legal and business documents, the suits also spotlighted the sensitivity of the exposed authentication secrets. The case is part of the broader 2024–2026 wave of data-breach class actions and remains unresolved.

Dropbox's Response / Official Position

Dropbox disclosed the breach via an 8-K filing and a Dropbox Sign blog post, reset passwords, rotated API keys and OAuth tokens, logged users out of connected devices, and emailed affected users. In the litigation, Dropbox moved to compel arbitration based on the terms plaintiffs accepted when signing documents through Dropbox Sign; the court granted the motion and later denied the plaintiffs' motion for reconsideration, sending the claims to individual arbitration, and no admission of liability has been reported.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation