Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

Product

Core sync & desktop client

78 documented issues affecting Core sync & desktop client, most severe first.

3 sources
Critical8,343 files lost in one documented case

The 2014 Selective Sync bug that permanently deleted users' files

A flaw in Dropbox's desktop Selective Sync feature permanently destroyed the files of users whose client crashed or was force-quit mid-operation — including one photographer who lost more than 8,000 irreplaceable images. Dropbox compensated affected users with a year of Dropbox Pro.

Reliability & Data Loss
Read documentation
4 sources
Critical68,648,009, per Troy Hunt's independent count (Dropbox described it as 'roughly 68 million')

The 2012 breach: 68 million user credentials stolen via a reused password

An attacker used a Dropbox employee's reused password to steal a file containing roughly 68 million users' email addresses and hashed passwords — a theft whose full scale only became public in 2016.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation
2 sources
Criticalfewer than a hundred, per Dropbox's final count (initially described as 'much less than 1 percent' of accounts that logged in during the window)

The 2011 authentication bug: any password unlocked any account

For nearly four hours on 19 June 2011, a code update left Dropbox accounts accessible with any password at all — anyone could sign in to any account by typing anything.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation
3 sources
Highpaying users 18.07M (down from 18.24M year over year)

Fiscal 2025 results and the flat 2026 guidance: a year of managed stagnation

Dropbox closed fiscal 2025 with revenue of about $2.52 billion, down roughly 1% year over year, paying users down to 18.07 million, and guidance for 2026 of essentially flat revenue — confirming that the core business has stopped growing even as margins expand.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

Beyond the headline user decline, Dropbox flagged elevated churn and downsell in its teams business through 2025 — customers cancelling or trading down to cheaper plans — a retention problem analysts called a structural drag that cost-cutting alone cannot fix.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation
3 sources
Highpaying users fell from ~18.22M (Q2 2024) to ~18.07M (Q3 2025)

Declining paying users and stalling revenue: the core business in retreat

After years of growth, Dropbox's paying-user count began falling and revenue turned negative year-over-year through 2025, as the company shrank managed-sales investment and exited product lines — raising questions about the durability of its core subscription business.

Product Changes & User BacklashPricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox can disable an account for policy violations — and when it does, all access to the account and its files is terminated at once. Users widely report being locked out with little explanation, and that some disablings are triggered by automated abuse-detection.

Reliability & Data LossAccount Lockouts & Support Failures
Read documentation

If a Dropbox account exceeds its (often downgraded) storage quota, users may lose the ability to sync, upload, share, move or even preview files — and if it stays over the limit, Dropbox 'may delete files you own' to force the account back under quota.

Reliability & Data LossPricing & Business PracticesAccount Lockouts & Support Failures
Read documentation

Apple's deprecation of kernel extensions forced Dropbox to rebuild its macOS sync on Apple's File Provider framework; macOS 12.3 (2022) removed the kext support Dropbox's online-only files relied on, changing behavior and temporarily breaking how third-party apps opened online-only files.

Product Changes & User BacklashDeveloper, API & Platform
Read documentation

Dropbox's forced migration to Apple's File Provider framework on macOS Monterey and Ventura brought runaway CPU usage, stalled syncing, and reports of locally available folders silently reverting to online-only — experienced by some users as data loss.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

The 2018 CLOUD Act amended US law so that a US-based provider like Dropbox can be compelled to produce a user's data regardless of which country the data is physically stored in — meaning a US warrant can reach an overseas user's files.

Privacy & Encryption ConcernsLegal Actions & LawsuitsGovernment Access & Surveillance
Read documentation

In January 2017 files and folders that users had deleted — in some cases as far back as 2009 — suddenly reappeared in their accounts, revealing that 'deleted' data had been retained on Dropbox's servers far longer than its own policy promised.

Privacy & Encryption ConcernsReliability & Data Loss
Read documentation
3 sources
Highall pre-mid-2012 users who had not changed their password

The 2016 mass password reset: forcing millions to re-secure pre-2012 accounts

When the full 2012 credential dump resurfaced in 2016, Dropbox forced a password reset on every user who had signed up before mid-2012 and never changed their password — a sweeping operational response that, for many, was the first sign anything was wrong.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

At Black Hat USA 2015, Imperva researchers showed that stealing a single synchronization token let an attacker take over a Dropbox account and read its files indefinitely — and that, in Dropbox's case, changing the password did not revoke the stolen token.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

After the 2013 PRISM disclosures named major US tech firms, Dropbox spent the following years documenting — through its own reports and advocacy — that it sits inside the same surveillance ecosystem: subject to NSLs, FISA orders and rising law-enforcement demands, with only banded, gagged disclosure permitted.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

A subtle bug in a maintenance script reinstalled the operating system on a small number of active production database machines, knocking Dropbox offline starting Friday 10 January 2014, with full service not restored until Sunday.

Reliability & Data Loss
Read documentation
3 sources
High0–249 national-security requests reported for 2013

National Security Letters and FISA orders: demands Dropbox can barely acknowledge

Dropbox is subject to National Security Letters and FISA orders that arrive with gag provisions barring it from disclosing even that it received them; the most it can publish is a band such as '0–249' national-security requests.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox has published a biannual Transparency Report since 2012, and its own figures document a steady, long-run climb in government and law-enforcement demands for user data — including reporting periods where US legal-process requests jumped by roughly a third.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Researcher Derek Newton showed that Dropbox's desktop client stored an unencrypted authentication token (host_id) in a local config.db file — copy that one value to another machine and you owned the victim's account, with no password and no notification.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Dropbox encrypts files at rest, but the encryption keys belong to Dropbox, not the user. This server-side model — chosen to enable deduplication, previews, and search — means the company can read user files, the root cause critics return to again and again.

Privacy & Encryption Concerns
Read documentation

Security researcher Christopher Soghoian filed a complaint with the U.S. Federal Trade Commission alleging that Dropbox made deceptive claims about its encryption, because Dropbox employees could in fact access users' files.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsLegal Actions & Lawsuits
Read documentation

Security researcher Christopher Soghoian filed an FTC complaint alleging Dropbox had told users their files were inaccessible even to Dropbox employees, while its actual architecture — and a quietly revised Terms of Service — made clear the company could decrypt and hand over files.

Privacy & Encryption ConcernsLegal Actions & Lawsuits
Read documentation

Dropbox's own status page logged eleven separate incidents between January and September 2026 — mostly brief, but including a roughly 93-hour shared-content-download degradation in June and an 11-hour, 46-minute Dropbox Protect failure in August.

Reliability & Data LossCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

Dropbox has reorganized around Dash, an AI-powered search assistant, repeatedly describing its core file-sync product as 'mature' — leaving longtime users uncertain how much future investment the service they actually pay for will receive.

Reliability & Data LossProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation
2 sources
Medium~700 million registered users (vs. 3B+ Google Workspace users)

Google's 2025 migration tool: a rival builds a one-click off-ramp from Dropbox

In November 2025 Google launched a tool to move files out of Dropbox Business into Google Drive, a pointed bid to convert Dropbox customers — and a sign of how exposed Dropbox's commodity-storage business is to free, bundled offerings from far larger rivals.

Product Changes & User BacklashPricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

A 2024 Proton analysis found Dropbox's privacy policy permits extensive data sharing with third parties — including Google, Amazon, OpenAI, Kissmetrics, and Stripe — and lets Dropbox volunteer user data to authorities in the vaguely defined 'public interest.'

Privacy & Encryption Concerns
Read documentation

A tracked vulnerability in the Dropbox desktop application for Windows could strip the 'Mark of the Web' flag from synced files, weakening a key warning that protects users from running downloaded, untrusted content.

Security Incidents & Data BreachesDeveloper, API & Platform
Read documentation

Dropbox runs industry hash-matching (PhotoDNA, NCMEC and IWF hash lists) and an unhashed-content classifier across files added to or shared on the service, reporting matches to NCMEC — a legitimate child-safety system that is also, by design, a server-side scan of users' private content.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Tied to Apple's File Provider requirements, Dropbox announced in 2023 that its Mac client could no longer sync to or store the Dropbox folder on an external drive, forcing all content onto the boot volume and breaking workflows built on large external archives.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

Since its 2018 IPO, Dropbox has steadily reoriented around higher-paying business customers and a 'Smart Workspace' strategy, layering price increases and feature-gating onto individual plans while shifting investment toward enterprise revenue.

Product Changes & User BacklashPricing & Business Practices
Read documentation

Dropbox deems a free account inactive after 12 months with no log-in or file activity; the account is then disabled and, after a further period, its files are deleted. Users widely report having data erased while assuming Dropbox was a safe long-term store.

Reliability & Data LossProduct Changes & User BacklashAccount Lockouts & Support Failures
Read documentation

Patent-assertion entity Motion Offense accused Dropbox's file-sharing and Smart Sync features of infringing four patents and sought roughly $35.7 million; a Waco, Texas jury returned a defense verdict in May 2023, finding no infringement and all four patents invalid.

Legal Actions & Lawsuits
Read documentation

Dropbox's Smart Sync depended on a macOS kernel extension to present space-saving 'online-only' placeholder files; when Apple deprecated third-party kexts in macOS 12.3, opening those online-only files could break until Dropbox re-engineered the feature.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

Entangled Media sued Dropbox over two patents on cloud-based file systems; the patent office declined to review the patents, and by August 2026 the court had ruled against Entangled Media on both patents at the district-court level and called off a scheduled trial, though it remains unknown whether final judgment has been entered or an appeal filed.

Legal Actions & LawsuitsCurrent / Ongoing Issues (2024–2026)
Read documentation
2 sources
Medium~19.3% of warrant-affected users in H1 2021 (indefinite gag)

Indefinite gag orders: the users Dropbox is barred from ever warning

Dropbox's own Transparency Report shows that a large share of the search warrants it receives arrive with indefinite non-disclosure orders, leaving the company unable to ever notify those users that the government took their data.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

The DropSmack proof-of-concept warned that synced Dropbox folders could be a covert C2 and exfiltration channel; multiple real malware families — including BoxCaon, Crutch and tooling used by Kimsuky — went on to abuse Dropbox folders and the Dropbox API exactly that way.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

European courts and regulators treat data held by US providers as inherently reachable by US surveillance under FISA Section 702 and the CLOUD Act — a structural concern that applies to any US-controlled cloud service, including Dropbox, regardless of where servers sit.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation
3 sources
MediumEU/EEA organizations and users

Schrems II: why EU users' files on Dropbox sit under a legal cloud

The EU's 2020 Schrems II ruling struck down the Privacy Shield framework over US surveillance, leaving EU organizations that store data with US providers like Dropbox needing extra safeguards — and unable to fully escape US legal reach.

Privacy & Encryption ConcernsLegal Actions & LawsuitsGovernment Access & Surveillance
Read documentation

Dropbox's 2019 redesign replaced its famously minimal sync-folder app with a heavy, Electron-based 'workspace' window — a Slack-like file manager that critics said abandoned the simple, reliable syncing that made Dropbox loved.

Reliability & Data LossProduct Changes & User Backlash
Read documentation
3 sources
MediumLinux desktop users on non-ext4 / encrypted volumes

2018: Dropbox cuts off every Linux filesystem but unencrypted ext4

Dropbox announced that from November 2018 its Linux client would sync only on unencrypted ext4, abruptly breaking sync for users on XFS, Btrfs, ZFS, and encrypted volumes — including encrypted ext4.

Reliability & Data LossProduct Changes & User BacklashDeveloper, API & Platform
Read documentation

From 7 November 2018 Dropbox dropped sync support on Linux for every filesystem except unencrypted ext4, instantly breaking syncing for users on XFS, ZFS, ext3, Btrfs, and encrypted setups — making their data unavailable through Dropbox overnight.

Reliability & Data LossProduct Changes & User Backlash
Read documentation
3 sources
Medium

The Linux ext4-only ultimatum: drop everything but one filesystem

Dropbox told Linux users that from November 2018 its client would sync only on unencrypted ext4, abruptly stripping support for XFS, Btrfs, ZFS, and encrypted setups — communicated as a terse desktop notification with little explanation.

Product Changes & User Backlash
Read documentation

A persistent class of complaints describes Dropbox files that sit indefinitely in a 'syncing' state and never finish, leaving users unsure whether their data was actually uploaded — in some reported cases for months, with support unable to resolve it.

Reliability & Data LossAccount Lockouts & Support Failures
Read documentation

Synchronoss Technologies accused Dropbox of infringing three data-synchronization patents; Dropbox won summary judgment of non-infringement and invalidity in 2019, and the Federal Circuit affirmed in 2021.

Legal Actions & Lawsuits
Read documentation

Researchers revealed that Dropbox's Mac client used a user's admin password to directly edit macOS's protected TCC.db permissions database, inserting itself into the Accessibility list — a privacy/trust list that grants near-total control over the machine — without a clear, informed prompt.

Security Incidents & Data BreachesPrivacy & Encryption ConcernsReliability & Data Loss
Read documentation

Because Dropbox holds the keys to decrypt users' files, a valid legal order doesn't just get a government encrypted data it can't read — it gets readable file content. The design choice is what makes lawful compulsion effective.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox runs every uploaded image and video through hash-matching systems such as Microsoft's PhotoDNA to detect known child sexual abuse material — automated scanning of users' private files that the company initially refused to explain.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

On 30 August 2015 Dropbox suffered a worldwide outage that locked users out of their files; the company blamed an issue that arose during routine internal maintenance.

Reliability & Data Loss
Read documentation

Responding to criticism of Dropbox's lack of zero-knowledge encryption, CEO Drew Houston framed the fact that Dropbox can access users' files as a deliberate 'trade-off between usability/convenience and security.'

Privacy & Encryption Concerns
Read documentation
2 sources
MediumUsers in mainland China

Blocked behind the Great Firewall: Dropbox in China since 2014

China's Great Firewall has blocked Dropbox since 2014 — at one point cutting users off from their own files overnight without warning — leaving the service reachable in the country only via VPNs that are themselves restricted.

Product Changes & User BacklashGovernment Access & Surveillance
Read documentation

Because Dropbox mirrors a permissive server namespace onto stricter local filesystems, files with disallowed characters, over-long paths, or trailing periods can fail to sync or be silently renamed — sometimes without any clear warning to the user.

Reliability & Data Loss
Read documentation

When Dropbox cannot reconcile two versions of a file, it preserves both — saving the loser as a duplicate stamped 'conflicted copy' — a data-safety mechanism that in practice creates lasting duplication and version confusion that users cannot turn off.

Reliability & Data LossProduct Changes & User Backlash
Read documentation
2 sources
Medium~7 million claimed by the Pastebin poster; Dropbox said the passwords had already been expired

The 2014 'Dropbox hack' that wasn't: leaked credentials and ransom

Hackers claimed to have stolen nearly 7 million Dropbox logins, posted batches on Pastebin, and demanded Bitcoin — but the credentials came from other breached services, not Dropbox itself.

Security Incidents & Data Breaches
Read documentation

On 10–11 January 2014 Dropbox went dark for roughly two hours after an internal maintenance error, while a group calling itself 1775 Sec falsely claimed to have breached it — a hoax that briefly stoked panic about user data.

Security Incidents & Data BreachesReliability & Data Loss
Read documentation

At Black Hat Europe 2013, a researcher demonstrated 'DropSmack,' a technique that abused Dropbox sync to slip malware past corporate firewalls and quietly exfiltrate company files.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

At USENIX WOOT 2013, Dhiru Kholia and Przemyslaw Wegrzyn unpacked and decompiled Dropbox's obfuscated-Python desktop client, demonstrated SSL interception via code injection, and described a way to hijack accounts and bypass two-factor authentication.

Security Incidents & Data BreachesPrivacy & Encryption Concerns
Read documentation

Among the classified NSA PRISM documents leaked by Edward Snowden, Dropbox appeared as a provider the surveillance program planned to add, listed as 'coming soon' — placing the company squarely inside the post-Snowden surveillance debate.

Privacy & Encryption Concerns
Read documentation

Q-CERT researchers found that because Dropbox did not verify email addresses at signup, an attacker who already had a victim's password could register a near-duplicate email, enable 2FA on it, and use the resulting emergency code to switch off the real account's two-step verification.

Security Incidents & Data Breaches
Read documentation

Dropbox splits files into blocks, hashes each with SHA-256, and stores only one copy of any block it already holds — a cost-saving design that researcher Christopher Soghoian warned could leak whether a given file already exists on Dropbox's servers.

Privacy & Encryption Concerns
Read documentation

The 2001 USA PATRIOT Act expanded US government access to records held by domestic companies and became the original reason foreign organizations distrusted storing data with US cloud providers — a concern that still attaches to Dropbox today.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Under the 1986 Stored Communications Act, US law enforcement can obtain a Dropbox user's basic subscriber records with a subpoena, account usage records with a court order, and the actual contents of their files with a search warrant — a tiered framework Dropbox publishes in its own guidelines.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

Dropbox uses cookies and machine learning to profile how engaged each user is — analyzing connected devices, storage used, file content, and sharing actions — to market premium services, with regional differences in what is on by default.

Privacy & Encryption Concerns
Read documentation

Datanet LLC sued Dropbox in October 2022 over two patents on automatic real-time file management; Dropbox challenged the patents at the patent office, and the district-court docket closed in March 2024.

Legal Actions & Lawsuits
Read documentation

After Apple Silicon Macs shipped in late 2020, Dropbox went nearly a year without a native build, forcing its always-on sync daemon to run under Rosetta 2 emulation — to mounting user fury — before committing to a native release in 2022.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

Topia Technology sued Dropbox and other cloud-storage companies over two file-synchronization patents; rather than fight in court, Dropbox and Box challenged the patents at the Patent Trial and Appeal Board, which found the claims unpatentable — a result later affirmed by the Federal Circuit.

Legal Actions & Lawsuits
Read documentation

Users complain that the Dropbox desktop app sets itself to launch at startup, embeds itself in Windows File Explorer and macOS Finder, and is difficult to fully remove — with 'failed to uninstall' errors and leftover launch agents, caches, and folders that must be cleaned out by hand.

Product Changes & User Backlash
Read documentation

Long-running, widely reported complaints describe the Dropbox desktop client consuming excessive CPU, disk, memory, and battery — sometimes pinning processors above 100% and draining laptop batteries even when nothing is actively syncing.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

Patent-assertion entity SynKloud Technologies sued Dropbox in the Western District of Texas over patents on wireless-device access to remote storage; Dropbox's bid to move the case to California was denied, while SynKloud's broader patent campaign unraveled at the patent office.

Legal Actions & Lawsuits
Read documentation

Linux users found Dropbox's system-tray icon — their primary way to see sync status and open the menu — broken or missing as desktops moved away from legacy tray icons toward AppIndicator, leaving Dropbox's status menu unreliable across popular distributions.

Product Changes & User Backlash
Read documentation
3 sources
Low

Project Infinite to Smart Sync: the rebrand that gated a marquee feature

Dropbox demoed 'Project Infinite' in 2016 as a way to see all cloud files on the desktop without using disk space, then shipped it in January 2017 rebranded as 'Smart Sync' — but restricted it to paying Business and Professional tiers rather than the free product its demo had implied.

Product Changes & User BacklashPricing & Business Practices
Read documentation

Dropbox's Smart Sync feature, meant to keep files 'online-only' to free local disk space, has repeatedly failed in the opposite direction — quietly re-downloading online-only files and filling up users' drives, or reverting their carefully chosen local/online states.

Reliability & Data LossProduct Changes & User Backlash
Read documentation

Names that are distinct on Dropbox's case-sensitive, Unicode-tolerant servers but identical on Windows or macOS collide on sync, and Dropbox resolves the clash by silently appending '(Case Conflict)' or '(Unicode Encoding Conflict)' to one of the files.

Reliability & Data Loss
Read documentation
2 sources
LowUsers in sanctioned regions (Crimea, North Korea, Syria, others)

Switched off by sanctions: no Dropbox in Crimea, North Korea, and Syria

To comply with US trade sanctions and embargoes, Dropbox does not provide service in regions such as Crimea, North Korea, and Syria — meaning users there can be cut off from their existing files by their provider's home-country law.

Government Access & SurveillanceAccount Lockouts & Support Failures
Read documentation

During the August 2015 global outage, Dropbox's status page reported service restored while many users were still locked out — a documented gap between the company's stated status and the actual experience of its users.

Reliability & Data LossAccount Lockouts & Support Failures
Read documentation

Because gag orders bar providers from confirming secret national-security demands, some companies post a 'warrant canary' — a standing statement that disappears if such a demand arrives. Dropbox relies on banded transparency reporting rather than a canary, leaving the most sensitive demands invisible to users.

Privacy & Encryption ConcernsGovernment Access & Surveillance
Read documentation

As thousands of intercepted Snapchat photos leaked in the so-called 'Snappening,' early reports tied Dropbox to the incident — but Dropbox flatly denied any involvement, and the actual leaks came from third-party apps and unrelated breaches, not Dropbox's systems.

Security Incidents & Data Breaches
Read documentation

Days after Dropbox disclosed the June 2011 bug that briefly let anyone sign into any account with any password, a plaintiff filed a class action alleging privacy and consumer-protection violations; the case was terminated within four months.

Security Incidents & Data BreachesLegal Actions & Lawsuits
Read documentation