Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Wong v. Dropbox: a class action over the 2011 'any password' bug

2011

LowStatus: HistoricalProduct: Core syncYear: 2011

Days after Dropbox disclosed the June 2011 bug that briefly let anyone sign into any account with any password, a plaintiff filed a class action alleging privacy and consumer-protection violations; the case was terminated within four months.

What happened

On 19 June 2011 Dropbox disclosed an authentication bug that, for a window of about four hours, allowed any logged-in session to access any account without the correct password. Days later, on 22 June 2011, plaintiff Cristina Wong filed a putative class action against Dropbox in the U.S. District Court for the Northern District of California (Wong v. Dropbox, Inc., No. 4:11-cv-03092), before Judge Laurel Beeler.

The complaint alleged that the security lapse violated California's Unfair Competition Law, constituted an invasion of privacy, and amounted to negligence and breach of warranty, on behalf of affected Dropbox users. The case was terminated on 18 October 2011 — under four months after it was filed — but the specific disposition (whether by voluntary dismissal, an early settlement, or otherwise) is not confirmed in the accessible record, so no definitive outcome is asserted here beyond the early termination.

The suit is the litigation counterpart to the well-documented 2011 authentication bug, translating that security incident into a consumer lawsuit almost immediately.

Impact

Wong v. Dropbox shows how quickly a publicized security failure could become litigation, and it is an early data point in the pattern of consumer suits following Dropbox security incidents — a pattern that recurs through the 2012 credential theft and the 2024 Dropbox Sign breach. Its rapid termination, however, reflects the difficulty plaintiffs faced in proving concrete harm from a short-lived bug.

Dropbox's Response / Official Position

Dropbox had publicly disclosed and apologized for the underlying authentication bug in a June 2011 blog post and said it had fixed the issue within hours. It is not publicly documented to have admitted any liability in the Wong litigation, which terminated within months.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation
3 sources
HighHundreds of thousands (Sign-breach class, now in arbitration)

2025: Dropbox forces the Sign-breach class action into private arbitration

A federal judge compelled the users suing over the 2024 Dropbox Sign breach into individual arbitration — finding that by clicking 'I agree' to sign a document they had accepted Dropbox's terms — and then denied reconsideration, effectively shutting the class action out of court.

Legal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation