Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

The archive

Issues Database

Every documented issue, searchable and filterable by category, year, and keyword. Toggle between grid and timeline views, and export the filtered set to CSV.

Datanet LLC sued Dropbox in October 2022 over two patents on automatic real-time file management; Dropbox challenged the patents at the patent office, and the district-court docket closed in March 2024.

Legal Actions & Lawsuits
Read documentation

Dropbox Sign (formerly HelloSign) is sold as a wholly separate subscription — a free tier capped at three documents per month, then Essentials at about $15, Standard at about $25, and Premium at roughly $40 per user per month — so existing Dropbox storage customers must pay again, per seat, to sign documents.

Pricing & Business Practices
Read documentation

Entangled Media sued Dropbox over two patents on cloud-based file systems; the patent office declined to review the patents, and by August 2026 the court had ruled against Entangled Media on both patents at the district-court level and called off a scheduled trial, though it remains unknown whether final judgment has been entered or an appeal filed.

Legal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation

In 2022 Dropbox rebranded HelloSign — the established e-signature service it had acquired in 2019 — as 'Dropbox Sign,' also renaming HelloWorks to Dropbox Forms and HelloFax to Dropbox Fax, folding a recognized independent brand under the Dropbox umbrella.

Product Changes & User BacklashDeveloper, API & Platform
Read documentation

Many third-party integrations request broad, full-Dropbox access rather than scoped, folder-limited permissions — so a single connected app, if compromised, can expose everything in an account.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsDeveloper, API & Platform
Read documentation
2 sources
High130 internal GitHub repositories; a few thousand employee, customer, sales-lead, and vendor names and email addresses

The 2022 phishing breach: 130 internal GitHub repositories stolen

A phishing campaign impersonating the CI provider CircleCI tricked Dropbox employees into handing over credentials and 2FA codes, letting attackers copy 130 of Dropbox's private source-code repositories.

Security Incidents & Data Breaches
Read documentation

ESET and Avast documented the Worok espionage group's 'DropBoxControl' backdoor, which abused the Dropbox API as its entire command-and-control channel — reading commands from, and uploading stolen data to, ordinary files in a Dropbox account.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Dropbox's forced migration to Apple's File Provider framework on macOS Monterey and Ventura brought runaway CPU usage, stalled syncing, and reports of locally available folders silently reverting to online-only — experienced by some users as data loss.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

Dropbox's API lets connected third-party apps request 'Full Dropbox' access to a user's entire account, and broad OAuth scopes mean an app users link for one task can often read far more than they expect.

Privacy & Encryption ConcernsDeveloper, API & Platform
Read documentation
2 sources
MediumDozens of current/former employees

2021: dozens of Dropbox employees allege gender discrimination in pay and promotion

Dozens of current and former Dropbox employees — many women of color — alleged systemic gender disparities in pay, promotion, and treatment, in a report compiled by a former staff researcher that Dropbox strongly contested.

Workplace, Culture & Labor
Read documentation

After Apple Silicon Macs shipped in late 2020, Dropbox went nearly a year without a native build, forcing its always-on sync daemon to run under Rosetta 2 emulation — to mounting user fury — before committing to a native release in 2022.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

On 30 September 2021 Dropbox stopped issuing the never-expiring access tokens many integrations relied on, switching to short-lived tokens plus refresh tokens — backups, scripts, and self-hosted tools that hard-coded a static token broke unless rewritten.

Developer, API & Platform
Read documentation