Product
DocSend & FormSwift
3 documented issues affecting DocSend & FormSwift, most severe first.
ConsentFix (2026): Microsoft 365 OAuth phishing that hides its lures on Dropbox and DocSend
ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.
After spending about $165M on DocSend (2021) and $95M on FormSwift (2022), Dropbox discontinued DocSend's Send & Track analytics in March 2025 and began winding down FormSwift in 2025 — abandoning roughly $260M of acquisitions while citing the wind-down as a drag on its own paying-user numbers.
Dropbox spent $165 million on DocSend in 2021 and $95 million on FormSwift in 2022, promising to weave them into an 'end-to-end agreement workflow' — continuing its pattern of acquiring standalone tools whose long-term integration and survival under Dropbox is uncertain.