Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

The archive

Issues Database

Every documented issue, searchable and filterable by category, year, and keyword. Toggle between grid and timeline views, and export the filtered set to CSV.

As thousands of intercepted Snapchat photos leaked in the so-called 'Snappening,' early reports tied Dropbox to the incident — but Dropbox flatly denied any involvement, and the actual leaks came from third-party apps and unrelated breaches, not Dropbox's systems.

Security Incidents & Data Breaches
Read documentation
3 sources
Critical8,343 files lost in one documented case

The 2014 Selective Sync bug that permanently deleted users' files

A flaw in Dropbox's desktop Selective Sync feature permanently destroyed the files of users whose client crashed or was force-quit mid-operation — including one photographer who lost more than 8,000 irreplaceable images. Dropbox compensated affected users with a year of Dropbox Pro.

Reliability & Data Loss
Read documentation

Researchers found that Dropbox's shared links to supposedly private documents could leak to third parties — exposed through browser referer headers and, in some cases, surfacing in Google search results — revealing tax returns, bank records, and business plans.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

A subtle bug in a maintenance script reinstalled the operating system on a small number of active production database machines, knocking Dropbox offline starting Friday 10 January 2014, with full service not restored until Sunday.

Reliability & Data Loss
Read documentation

On 10–11 January 2014 Dropbox went dark for roughly two hours after an internal maintenance error, while a group calling itself 1775 Sec falsely claimed to have breached it — a hoax that briefly stoked panic about user data.

Security Incidents & Data BreachesReliability & Data Loss
Read documentation

At Black Hat Europe 2013, a researcher demonstrated 'DropSmack,' a technique that abused Dropbox sync to slip malware past corporate firewalls and quietly exfiltrate company files.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

At USENIX WOOT 2013, Dhiru Kholia and Przemyslaw Wegrzyn unpacked and decompiled Dropbox's obfuscated-Python desktop client, demonstrated SSL interception via code injection, and described a way to hijack accounts and bypass two-factor authentication.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Among the classified NSA PRISM documents leaked by Edward Snowden, Dropbox appeared as a provider the surveillance program planned to add, listed as 'coming soon' — placing the company squarely inside the post-Snowden surveillance debate.

Privacy & Encryption Concerns
Read documentation
3 sources
High0–249 national-security requests reported for 2013

National Security Letters and FISA orders: demands Dropbox can barely acknowledge

Dropbox is subject to National Security Letters and FISA orders that arrive with gag provisions barring it from disclosing even that it received them; the most it can publish is a band such as '0–249' national-security requests.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Q-CERT researchers found that because Dropbox did not verify email addresses at signup, an attacker who already had a victim's password could register a near-duplicate email, enable 2FA on it, and use the resulting emergency code to switch off the real account's two-step verification.

Security Incidents & Data Breaches
Read documentation

Dropbox has published a biannual Transparency Report since 2012, and its own figures document a steady, long-run climb in government and law-enforcement demands for user data — including reporting periods where US legal-process requests jumped by roughly a third.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
4 sources
Critical68,648,009, per Troy Hunt's independent count (Dropbox described it as 'roughly 68 million')

The 2012 breach: 68 million user credentials stolen via a reused password

An attacker used a Dropbox employee's reused password to steal a file containing roughly 68 million users' email addresses and hashed passwords — a theft whose full scale only became public in 2016.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation