Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Discontinuing Dropbox Vault: the PIN-protected folder turned ordinary

Announced January 2025 (converted to a normal folder 4 March 2025)

MediumStatus: HistoricalProduct: Dropbox VaultYear: 2025

Dropbox discontinued Dropbox Vault, the PIN-protected folder for sensitive files, on 4 March 2025 — automatically converting every Vault into an ordinary, un-PIN'd Dropbox folder.

What happened

Dropbox Vault was marketed as a secure place for users' most sensitive documents — passports, tax records, financial files — behind a separate six-digit PIN. It was offered as a security perk of paid plans and pitched as 'an added layer of protection.'

In January 2025 Dropbox announced that Vault would be discontinued on 4 March 2025. On that date, every user's Vault was automatically converted into a standard Dropbox folder, with the PIN requirement removed and the files left in place. Dropbox said it was discontinuing Vault to 'concentrate efforts on further improving existing security features and building new capabilities around advanced data protection.'

The announcement drew significant backlash on Dropbox's own forums. Beyond the loss of a feature users had relied on, the automatic conversion raised a pointed question: if Dropbox could silently move 'protected' files out of the Vault and strip the PIN without any user action, how meaningful had that protection ever been? Critics framed it as another example of Dropbox removing a feature with thin justification.

Impact

The Vault shutdown landed especially hard because it removed a security feature, not just a convenience — and the automatic, PIN-less conversion exposed that the Vault's protection was a UI gate rather than independent encryption. It fed the broader narrative of Dropbox quietly retiring consumer-facing features and undercut trust in Dropbox's security marketing at the same time it was winding down Dropbox Passwords.

Dropbox's Response / Official Position

Dropbox notified users and posted a community announcement stating Vault would be discontinued on 4 March 2025, that Vaults would automatically become regular folders with files intact, and that the move let it focus on improving existing security features and advanced data protection. It did not reverse the decision despite forum objections.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation