Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Dropbox Sign for integrators: the HelloSign rebrand, then a breach that rotated their keys

2022 rebrand; 2024 breach fallout

HighStatus: HistoricalProduct: Dropbox Sign API (formerly HelloSign)Year: 2024

The HelloSign API was rebranded to the Dropbox Sign API in 2022, and after the 2024 Dropbox Sign breach the company rotated API keys and OAuth tokens — meaning developers who had embedded e-signature functionality had to update credentials and re-establish connections, not just rename a product.

What happened

Dropbox acquired HelloSign in 2019 and, in October 2022, rebranded it to Dropbox Sign — the HelloSign API became the Dropbox Sign API. Dropbox told developers the rebrand itself was low-impact: existing integrations would keep working with 'HelloSign' simply replaced by 'Dropbox Sign,' and credentials were unchanged. Companion products were renamed too (HelloFax to Dropbox Fax, HelloWorks to Dropbox Forms).

The more serious consequence for integrators came later. In the April–May 2024 Dropbox Sign security incident, an attacker reached the Dropbox Sign customer database and exposed authentication material including API keys, OAuth tokens, and MFA data. In response Dropbox reset passwords, logged users out, and rotated API keys and OAuth tokens. (The breach as a security event is covered by the existing 2024-dropbox-sign-breach entry; the developer angle is distinct.) For any application that had embedded Dropbox Sign signing into its own product, that rotation was a forced break: previously working API keys and tokens stopped working, and developers had to obtain and deploy new credentials and re-authorize OAuth connections to restore their e-signature flows.

Impact

Integrators of Dropbox Sign experienced the rebrand as cosmetic but the 2024 breach response as operationally disruptive — a mandatory credential rotation that broke live signing integrations until updated. It illustrates how a security incident in one acquired product cascades into unplanned engineering work for every third party that built on its API, compounding the developer-trust cost of the breach itself.

Dropbox's Response / Official Position

Dropbox published 'Rebrand FAQs' and product-update posts in 2022 stating integrations would continue to work with only the name changing. For the 2024 incident, the Dropbox Sign blog and the company's SEC 8-K disclosed that it had reset credentials and rotated API keys and OAuth tokens and instructed affected customers to take action.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation