Product
Shared links & file hosting
5 documented issues affecting Shared links & file hosting, most severe first.
Researchers found that Dropbox's shared links to supposedly private documents could leak to third parties — exposed through browser referer headers and, in some cases, surfacing in Google search results — revealing tax returns, bank records, and business plans.
Dropbox links as the first hop: the AsyncRAT campaign that hid its malware behind Dropbox URLs and TryCloudflare tunnels
Forcepoint X-Labs and The Hacker News documented a phishing campaign that used Dropbox URLs, not attachments, as the first link in a chain — ZIP to internet shortcut to .lnk to JavaScript to .BAT to a malicious Python package — that ultimately deployed AsyncRAT, Venom RAT, and XWorm via temporary TryCloudflare tunnels.
Phishing pages hosted on Dropbox: the 2024 'BEC 3.0' credential-harvesting wave
Check Point recorded thousands of attacks in which criminals hosted credential-harvesting documents on Dropbox itself, so the phishing emails came genuinely from [email protected] and sailed past filters that trust the Dropbox domain.
Dropbox converted the long-standing Public folder into an ordinary private folder and then disabled all of its public links on 1 September 2017, breaking countless URLs people had embedded across the web with no automatic migration.
A viral 2014 incident revealed that Dropbox compares the cryptographic hashes of files users try to share against a blacklist of DMCA-flagged content and blocks matches — surprising users who assumed their files were entirely private.