Search the Dropbox Watchdog archive
The archive
Every documented issue, searchable and filterable by category, year, and keyword. Toggle between grid and timeline views, and export the filtered set to CSV.
While laying off about 20% of staff in October 2024, Dropbox was simultaneously running large share buybacks — authorizing $1.2 billion in December 2024 and a further $1.5 billion in September 2025 — directing billions to shareholders even as it cut jobs and trimmed product investment.
A tracked vulnerability in the Dropbox desktop application for Windows could strip the 'Mark of the Web' flag from synced files, weakening a key warning that protects users from running downloaded, untrusted content.
After Dropbox disclosed the April 2024 Dropbox Sign breach, affected users filed proposed class actions in federal court alleging Dropbox negligently failed to protect their data and did not give prompt, adequate notice; the claims are allegations and the consolidated litigation followed in the Northern District of California.
Patent-assertion entity Daedalus Blue, holder of former IBM patents, sued Dropbox in August 2024, accusing the Dropbox API, the Magic Pocket storage system, and the Nautilus search engine of infringement; Dropbox's eligibility challenge was granted only in part, leaving the case alive.
The Dropbox Dash Chrome extension requests permission to 'read and change all your data on all websites' and imports up to 90 days of browsing history — URLs, page titles, and page contents — to power its AI search.
The HelloSign API was rebranded to the Dropbox Sign API in 2022, and after the 2024 Dropbox Sign breach the company rotated API keys and OAuth tokens — meaning developers who had embedded e-signature functionality had to update credentials and re-establish connections, not just rename a product.
Beyond credential phishing, attackers have used Dropbox links to deliver malware — distributing remote-access trojans such as AsyncRAT through Dropbox-hosted archives and shortcut files that abuse the service's trusted reputation to get past defenses.
Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.
Dropbox Basic (free) users get no email, chat or phone support — only the help center and community forum. Even paying Plus and Professional customers must first pass through a Dropbox AI assistant before they can reach email or live chat.
Dropbox runs industry hash-matching (PhotoDNA, NCMEC and IWF hash lists) and an unhashed-content classifier across files added to or shared on the service, reporting matches to NCMEC — a legitimate child-safety system that is also, by design, a server-side scan of users' private content.
Dropbox uses cookies and machine learning to profile how engaged each user is — analyzing connected devices, storage used, file content, and sharing actions — to market premium services, with regional differences in what is on by default.
Check Point recorded thousands of attacks in which criminals hosted credential-harvesting documents on Dropbox itself, so the phishing emails came genuinely from [email protected] and sailed past filters that trust the Dropbox domain.
191 issues