The archive
Issues Database
Every documented issue, searchable and filterable by category, year, and keyword. Toggle between grid and timeline views, and export the filtered set to CSV.
'I take full responsibility': Drew Houston's 2024 layoff memo and the morale fallout
The internal memo behind Dropbox's October 2024 cut of about 528 jobs admitted the company had 'over-invested' and grown too many layers of management; the second mass layoff in 18 months left employees rattled about the company's direction and stability.
2024: Dropbox's 2012 credentials resurface in the 'Mother of All Breaches'
In January 2024 a 26-billion-record compilation dubbed the 'Mother of All Breaches' surfaced online — and the 68 million credentials stolen from Dropbox in 2012 were among the datasets bundled into it.
A 2024 Proton analysis found Dropbox's privacy policy permits extensive data sharing with third parties — including Google, Amazon, OpenAI, Kissmetrics, and Stripe — and lets Dropbox volunteer user data to authorities in the vaguely defined 'public interest.'
Billions for buybacks, thousands of jobs cut: capital returns over headcount
While laying off about 20% of staff in October 2024, Dropbox was simultaneously running large share buybacks — authorizing $1.2 billion in December 2024 and a further $1.5 billion in September 2025 — directing billions to shareholders even as it cut jobs and trimmed product investment.
A tracked vulnerability in the Dropbox desktop application for Windows could strip the 'Mark of the Web' flag from synced files, weakening a key warning that protects users from running downloaded, untrusted content.
After Dropbox disclosed the April 2024 Dropbox Sign breach, affected users filed proposed class actions in federal court alleging Dropbox negligently failed to protect their data and did not give prompt, adequate notice; the claims are allegations and the consolidated litigation followed in the Northern District of California.
Patent-assertion entity Daedalus Blue, holder of former IBM patents, sued Dropbox in August 2024, accusing the Dropbox API, the Magic Pocket storage system, and the Nautilus search engine of infringement; Dropbox's eligibility challenge was granted only in part, leaving the case alive.
Dropbox Dash's browser extension demands 'read and change all your data on all websites'
The Dropbox Dash Chrome extension requests permission to 'read and change all your data on all websites' and imports up to 90 days of browsing history — URLs, page titles, and page contents — to power its AI search.
Dropbox Sign for integrators: the HelloSign rebrand, then a breach that rotated their keys
The HelloSign API was rebranded to the Dropbox Sign API in 2022, and after the 2024 Dropbox Sign breach the company rotated API keys and OAuth tokens — meaning developers who had embedded e-signature functionality had to update credentials and re-establish connections, not just rename a product.
Dropbox links as the first hop: the AsyncRAT campaign that hid its malware behind Dropbox URLs and TryCloudflare tunnels
Forcepoint X-Labs and The Hacker News documented a phishing campaign that used Dropbox URLs, not attachments, as the first link in a chain — ZIP to internet shortcut to .lnk to JavaScript to .BAT to a malicious Python package — that ultimately deployed AsyncRAT, Venom RAT, and XWorm via temporary TryCloudflare tunnels.
Guiffre v. Dropbox: the class action over the 2024 Dropbox Sign breach
Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.
Dropbox Basic (free) users get no email, chat or phone support — only the help center and community forum. Even paying Plus and Professional customers must first pass through a Dropbox AI assistant before they can reach email or live chat.