Search the Dropbox Watchdog archive
Chronology
A chronological record of Dropbox's documented issues from 2010 to 2026. Filter by category and click any event for the full, sourced entry.
191 events
Announced 2025 (effective 1 January 2026)
Because some official Dropbox SDKs pinned root certificates, Dropbox's switch to a new certificate root starting 1 January 2026 means apps on the Java, .NET, or Python SDK must upgrade to specific minimum versions or lose access to the API.
2025–2026
With revenue flat-to-declining and its AI product Dash still showing no monetization metrics, analysts moved Dropbox to 'sell' — warning that buyback-fueled EPS masks a structurally stalled business.
2022–2026
By the end of 2025 Dropbox employed about 2,113 people — its smallest headcount since 2017, and roughly 32% below its late-2022 peak — one of the steepest sustained workforce reductions among profitable mid-cap software firms.
May 2026
In May 2026 Drew Houston announced he would step back as CEO after 19 years, naming product chief Ashraf Alkarmi as successor in a co-CEO transition — a handoff that arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.
Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.
February 2026 (FY2025 results)
Dropbox closed fiscal 2025 with revenue of about $2.52 billion, down roughly 1% year over year, paying users down to 18.07 million, and guidance for 2026 of essentially flat revenue — confirming that the core business has stopped growing even as margins expand.
2023–2026 (ongoing)
Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.
2025
A consumer law firm opened an investigation into Dropbox Plus auto-renewals in 2025, as strengthened automatic-renewal laws in California and New York raised the bar for consent, reminders, and easy cancellation.
October 2025
Dropbox discontinued the Dropbox Paper mobile and desktop apps on 9 October 2025, leaving the once-flagship collaborative-document product accessible only through a web browser.
A federal judge compelled the users suing over the 2024 Dropbox Sign breach into individual arbitration — finding that by clicking 'I agree' to sign a document they had accepted Dropbox's terms — and then denied reconsideration, effectively shutting the class action out of court.
March 2025
Dropbox discontinued Dropbox Capture — its screen-recording and screenshot tool — on 24 March 2025, removing the app and the ability to create new recordings.
2025 onward
A pension fund shareholder sued Dropbox and its leadership in the Delaware Court of Chancery in 2025 over the company's plan to reincorporate in Nevada, alleging the move favored controlling stockholder and CEO Andrew Houston — in what was reported as the first court challenge to Delaware's controversial SB 21 corporate-law amendments.
Activist investor Half Moon Capital pressed Dropbox to dismantle the dual-class share structure that gives co-founder Drew Houston majority voting control, arguing that entrenched founder control and slowing growth were holding back value as the stock languished near multi-year lows.
2019–2026
A persistent pattern of consumer complaints describes Dropbox auto-renewing annual subscriptions without clear advance notice, burying the downgrade option, and refusing refunds for unused time — practices now drawing legal scrutiny under state automatic-renewal laws.
2024–2026 (ongoing)
Dropbox has reorganized around Dash, an AI-powered search assistant, repeatedly describing its core file-sync product as 'mature' — leaving longtime users uncertain how much future investment the service they actually pay for will receive.
2021–2026
After spending about $165M on DocSend (2021) and $95M on FormSwift (2022), Dropbox discontinued DocSend's Send & Track analytics in March 2025 and began winding down FormSwift in 2025 — abandoning roughly $260M of acquisitions while citing the wind-down as a drag on its own paying-user numbers.
While cutting roughly a third of its workforce across three rounds, Dropbox spent heavily on share buybacks and maintained substantial executive compensation — a contrast that drew criticism over how the company allocates its gains.
Beyond the headline user decline, Dropbox flagged elevated churn and downsell in its teams business through 2025 — customers cancelling or trading down to cheaper plans — a retention problem analysts called a structural drag that cost-cutting alone cannot fix.
Dash connects to Google Workspace, Microsoft 365, Slack, Notion and more, and routes queries through large language models — leaving users to trust Dropbox's contractual assurances that connected and indexed data is not used to train third-party AI models.
After years of growth, Dropbox's paying-user count began falling and revenue turned negative year-over-year through 2025, as the company shrank managed-sales investment and exited product lines — raising questions about the durability of its core subscription business.
Announced January 2025 (converted to a normal folder 4 March 2025)
Dropbox discontinued Dropbox Vault, the PIN-protected folder for sensitive files, on 4 March 2025 — automatically converting every Vault into an ordinary, un-PIN'd Dropbox folder.
Through 2025 Dropbox pushed Dash to general availability with self-serve sign-up and no IT required, marketing it as an AI assistant that indexes content across all of a user's connected apps — a model that, by design, reaches far beyond the files stored in Dropbox.
2024–2026
Dropbox's AI-powered universal search, Dash, is billed separately from storage at roughly $15 per user per month for teams and $35 per user per month for business — meaning the 'AI era' Dropbox used to justify layoffs arrives as an extra charge rather than an included feature.
2019 filesystem migration; mobile app discontinued October 2025
Dropbox Paper, once promoted as the future of collaborative documents, was steadily de-emphasized: docs were migrated into the ordinary Dropbox filesystem from 2019, scattering folders and breaking the app's structure, and the Paper mobile app was discontinued in October 2025.
Announced February 2025 (discontinued 24 March 2025)
Dropbox discontinued Dropbox Capture, its screen-recording and screenshot tool, on 24 March 2025 — leaving users unable to create new recordings and folding leftover content back into an ordinary Dropbox folder.
November 2025
In November 2025 Google launched a tool to move files out of Dropbox Business into Google Drive, a pointed bid to convert Dropbox customers — and a sign of how exposed Dropbox's commodity-storage business is to free, bundled offerings from far larger rivals.
2022–2025
The Better Business Bureau has logged more than 1,180 complaints against Dropbox over three years, dominated by surprise auto-renewal charges, denied refunds, and support tickets that vanish without resolution.
2025–2026 (ongoing)
Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.
Dropbox has staked its future on Dash, but through 2025 the AI product had not yet produced meaningful revenue offsetting the declining core — leaving analysts to question whether the layoffs-funded pivot is generating returns or simply burning the runway.
2023–2026
Independent review platforms tell a consistent story: a low ~1.9/5 on SiteJabber and a mixed Trustpilot record, dominated by complaints about surprise billing, lost files, and support that never reaches a human.
A succession of episodes — the 2023 OpenAI default-on toggle, the 2024 Dropbox Sign breach and litigation, two rounds of mass layoffs, declining users, and serial product shutdowns — has coalesced into a durable narrative that Dropbox is a fading incumbent whose trust and relevance are eroding.
Announced 2025 (fully discontinued 28 October 2025)
Dropbox shut down Dropbox Passwords, the password manager it had launched in 2020, in a phased 2025 wind-down ending 28 October 2025 — after which all stored credentials and payment cards were permanently deleted from its servers.
2018–2026
Dropbox publishes no list price for its Enterprise plan, requiring buyers to contact sales for a custom quote — an opacity that lets pricing vary by negotiation and obscures the true cost of moving an organization onto Dropbox.
October 2024
The internal memo behind Dropbox's October 2024 cut of about 528 jobs admitted the company had 'over-invested' and grown too many layers of management; the second mass layoff in 18 months left employees rattled about the company's direction and stability.
January 2024
In January 2024 a 26-billion-record compilation dubbed the 'Mother of All Breaches' surfaced online — and the 68 million credentials stolen from Dropbox in 2012 were among the datasets bundled into it.
2024
A 2024 Proton analysis found Dropbox's privacy policy permits extensive data sharing with third parties — including Google, Amazon, OpenAI, Kissmetrics, and Stripe — and lets Dropbox volunteer user data to authorities in the vaguely defined 'public interest.'
2024–2025
While laying off about 20% of staff in October 2024, Dropbox was simultaneously running large share buybacks — authorizing $1.2 billion in December 2024 and a further $1.5 billion in September 2025 — directing billions to shareholders even as it cut jobs and trimmed product investment.
A tracked vulnerability in the Dropbox desktop application for Windows could strip the 'Mark of the Web' flag from synced files, weakening a key warning that protects users from running downloaded, untrusted content.
After Dropbox disclosed the April 2024 Dropbox Sign breach, affected users filed proposed class actions in federal court alleging Dropbox negligently failed to protect their data and did not give prompt, adequate notice; the claims are allegations and the consolidated litigation followed in the Northern District of California.
2024 onward
Patent-assertion entity Daedalus Blue, holder of former IBM patents, sued Dropbox in August 2024, accusing the Dropbox API, the Magic Pocket storage system, and the Nautilus search engine of infringement; Dropbox's eligibility challenge was granted only in part, leaving the case alive.
2023–2024
The Dropbox Dash Chrome extension requests permission to 'read and change all your data on all websites' and imports up to 90 days of browsing history — URLs, page titles, and page contents — to power its AI search.
2022 rebrand; 2024 breach fallout
The HelloSign API was rebranded to the Dropbox Sign API in 2022, and after the 2024 Dropbox Sign breach the company rotated API keys and OAuth tokens — meaning developers who had embedded e-signature functionality had to update credentials and re-establish connections, not just rename a product.
Beyond credential phishing, attackers have used Dropbox links to deliver malware — distributing remote-access trojans such as AsyncRAT through Dropbox-hosted archives and shortcut files that abuse the service's trusted reputation to get past defenses.
May 2024
Within weeks of the Dropbox Sign breach disclosure, users filed a proposed class action in California federal court alleging Dropbox failed to protect their data and was slow to notify them.
Ongoing policy
Dropbox Basic (free) users get no email, chat or phone support — only the help center and community forum. Even paying Plus and Professional customers must first pass through a Dropbox AI assistant before they can reach email or live chat.
Ongoing
Dropbox runs industry hash-matching (PhotoDNA, NCMEC and IWF hash lists) and an unhashed-content classifier across files added to or shared on the service, reporting matches to NCMEC — a legitimate child-safety system that is also, by design, a server-side scan of users' private content.
Dropbox uses cookies and machine learning to profile how engaged each user is — analyzing connected devices, storage used, file content, and sharing actions — to market premium services, with regional differences in what is on by default.
September 2024
Check Point recorded thousands of attacks in which criminals hosted credential-harvesting documents on Dropbox itself, so the phishing emails came genuinely from [email protected] and sailed past filters that trust the Dropbox domain.
April–May 2024
An attacker compromised the production environment of Dropbox Sign (formerly HelloSign), exposing customer emails, usernames, phone numbers, hashed passwords, and authentication secrets including API keys, OAuth tokens, and MFA data.
Dropbox laid off about 528 employees — roughly 20% of its workforce — with CEO Drew Houston citing a maturing core business, soft demand, and the need for different AI skills as the company reorganized around its Dash product.
Following the 2024 Dropbox Sign breach, affected users filed proposed class-action lawsuits accusing Dropbox of failing to secure their data and of notifying victims too slowly. Dropbox has contested the claims, arguing the exposed data poses no identity-theft risk.
2014–2026
Dropbox's Terms of Service require binding individual arbitration and waive your right to join a class action — so even after a breach or billing dispute, most users cannot sue Dropbox or band together in court.
2008–2026
Dropbox has kept its free Basic plan at just 2GB since its early days, even as Google Drive offered 15GB, OneDrive 5GB, and rivals like Mega offered 20GB — leaving Dropbox with the stingiest free allowance among the major cloud providers.
Dropbox advertises Plus at $9.99 per month but charges $11.99 if you pay monthly instead of annually — a roughly 20% premium that pairs with non-refundable annual terms and auto-renewal to penalize the flexibility customers might want.
2021–2024
Dropbox cut staff three times in four years — ~11% in 2021, ~16% (about 500) in 2023, and ~20% (about 528) in 2024 — a churn that, beyond the financial framing, took a real toll on the employees and teams left behind.
2020–2026
State-aligned hacking groups, including North Korea's Kimsuky and ScarCruft, have repeatedly used the Dropbox API as a command-and-control and data-exfiltration channel, exploiting the fact that Dropbox traffic is trusted and rarely blocked.
2023
Dropbox rebranded HelloSign — the e-signature company it acquired in 2019 — as 'Dropbox Sign' in 2023, absorbing its identity into the Dropbox brand a year before the product suffered a major breach.
Ongoing pattern
If a user enables two-factor authentication and later loses their authenticator app, backup phone and emergency backup code, Dropbox support has told users it has no process to restore access — and the account, with all its files, is effectively lost.
Users widely report being charged after cancelling, billed on accounts they thought were closed, and unable to get Dropbox support to issue refunds — often resolved only after escalating to the BBB. The BBB has published a pattern alert tied to these complaints.
Dropbox can disable an account for policy violations — and when it does, all access to the account and its files is terminated at once. Users widely report being locked out with little explanation, and that some disablings are triggered by automated abuse-detection.
February 2023
Tied to Apple's File Provider requirements, Dropbox announced in 2023 that its Mac client could no longer sync to or store the Dropbox folder on an external drive, forcing all content onto the boot volume and breaking workflows built on large external archives.
Since its 2018 IPO, Dropbox has steadily reoriented around higher-paying business customers and a 'Smart Workspace' strategy, layering price increases and feature-gating onto individual plans while shifting investment toward enterprise revenue.
Dropbox's own engineering writing describes an analytics pipeline that logs fine-grained user-behavior events in its mobile apps — button clicks, navigation across screens, sign-in failures, upload timing — to study 'complex user scenarios.'
Dropbox deems a free account inactive after 12 months with no log-in or file activity; the account is then disabled and, after a further period, its files are deleted. Users widely report having data erased while assuming Dropbox was a safe long-term store.
2019–2024
Patent-assertion entity Motion Offense accused Dropbox's file-sharing and Smart Sync features of infringing four patents and sought roughly $35.7 million; a Waco, Texas jury returned a defense verdict in May 2023, finding no infringement and all four patents invalid.
After nearly four years of litigation, a Texas jury found Dropbox did not infringe four file-sharing patents asserted by Motion Offense LLC, defeating a roughly $35 million damages demand — part of a wider patent fight Dropbox largely won.
Dropbox offers no legacy-contact or memorialization feature. To obtain a deceased person's files, the next of kin must generally produce a court order compelling disclosure — a slow, expensive barrier that leaves grieving families locked out of irreplaceable data.
If a Dropbox account exceeds its (often downgraded) storage quota, users may lose the ability to sync, upload, share, move or even preview files — and if it stays over the limit, Dropbox 'may delete files you own' to force the account back under quota.
When an account exceeds its quota, Dropbox can halt syncing — the core function users depend on — until they delete files or pay more, while the path to downgrade a plan or step back to free is comparatively buried, wrapped in loss warnings, and locked behind non-refundable annual terms.
Dropbox teams must always have at least one admin, but when a sole admin leaves, is offboarded, or loses access, the rest of the team can be locked out of administration — and recovering control or transferring ownership often requires a slow special support process.
December 2023
Users discovered a 'third-party AI' setting that was switched on by default for most of the world, fueling fears that Dropbox was quietly feeding personal files to OpenAI. Dropbox said no data was passively sent and that files were not used to train models.
April 2023
In April 2023 Dropbox cut about 500 jobs — 16% of its workforce — with CEO Drew Houston attributing the move partly to 'the AI era of computing,' a framing critics saw as repackaging cost-cutting as strategic transformation at a profitable company.
August 2023
After years of advertising Dropbox Advanced as offering 'as much space as you need,' Dropbox replaced unlimited storage with metered tiers in August 2023, blaming a small group of heavy users including crypto miners and storage resellers.
A new Dropbox app starts in development status capped at 500 linked users, and once it reaches 50 users the developer has just two weeks to apply for and receive production approval — otherwise the app is frozen and cannot link any new users.
Dropbox promises a one-business-day email response on paid plans, but users widely report tickets sitting for days, being marked 'solved' without a fix, or being told to use the volunteer community forum — with some getting traction only after filing a BBB complaint.
Dropbox enforces rate limits it does not publish, returning HTTP 429 errors — including a separate too_many_write_operations limit triggered by parallel writes to the same folder — that can throttle backup tools and bulk integrations without warning.
Dropbox sends one-time verification codes for new-device or unusual logins, but when the code goes to an outdated phone number or an inbox the user can no longer reach, legitimate owners report being unable to sign in — and the questionnaire-based recovery often fails.
Dropbox made remote work a permanent default in 2020 and marketed 'Virtual First' as a model employer policy — but the lived reality of converted offices, evolving expectations, and culture-by-Slack drew its own employee friction.
November 2022
Dropbox acquired key assets of Boxcryptor, the zero-knowledge encryption tool many used to protect files on Dropbox — and Boxcryptor stopped taking new users and cancelled free accounts, pushing existing users to migrate.
2019–2022 (macOS 12.3 deadline)
Apple's deprecation of kernel extensions forced Dropbox to rebuild its macOS sync on Apple's File Provider framework; macOS 12.3 (2022) removed the kext support Dropbox's online-only files relied on, changing behavior and temporarily breaking how third-party apps opened online-only files.
2019–2022
Dropbox's Smart Sync depended on a macOS kernel extension to present space-saving 'online-only' placeholder files; when Apple deprecated third-party kexts in macOS 12.3, opening those online-only files could break until Dropbox re-engineered the feature.
DocSend acquired March 2021 ($165M); FormSwift acquired December 2022 ($95M)
Dropbox spent $165 million on DocSend in 2021 and $95 million on FormSwift in 2022, promising to weave them into an 'end-to-end agreement workflow' — continuing its pattern of acquiring standalone tools whose long-term integration and survival under Dropbox is uncertain.
2022–2024
Datanet LLC sued Dropbox in October 2022 over two patents on automatic real-time file management; Dropbox challenged the patents at the patent office, and the district-court docket closed in March 2024.
Dropbox Sign (formerly HelloSign) is sold as a wholly separate subscription — a free tier capped at three documents per month, then Essentials at about $15, Standard at about $25, and Premium at roughly $40 per user per month — so existing Dropbox storage customers must pay again, per seat, to sign documents.
2022 onward
Entangled Media sued Dropbox over two patents on cloud-based file systems; the patent office declined to review the patents, and in 2025 the court issued a mixed summary-judgment ruling, leaving the dispute contested rather than resolved.
August–November 2022
In 2022 Dropbox rebranded HelloSign — the established e-signature service it had acquired in 2019 — as 'Dropbox Sign,' also renaming HelloWorks to Dropbox Forms and HelloFax to Dropbox Fax, folding a recognized independent brand under the Dropbox umbrella.
Many third-party integrations request broad, full-Dropbox access rather than scoped, folder-limited permissions — so a single connected app, if compromised, can expose everything in an account.
A phishing campaign impersonating the CI provider CircleCI tricked Dropbox employees into handing over credentials and 2FA codes, letting attackers copy 130 of Dropbox's private source-code repositories.
ESET and Avast documented the Worok espionage group's 'DropBoxControl' backdoor, which abused the Dropbox API as its entire command-and-control channel — reading commands from, and uploading stolen data to, ordinary files in a Dropbox account.
2022–2023
Dropbox's forced migration to Apple's File Provider framework on macOS Monterey and Ventura brought runaway CPU usage, stalled syncing, and reports of locally available folders silently reverting to online-only — experienced by some users as data loss.
2021 (scoped-access rollout)
Dropbox's API lets connected third-party apps request 'Full Dropbox' access to a user's entire account, and broad OAuth scopes mean an app users link for one task can often read far more than they expect.
January 2021
Dropbox laid off about 11% of its workforce — roughly 315 employees — in January 2021, citing the need to flatten the organization and invest in growth, and replaced the head of its HelloSign unit.
February 2021
Dozens of current and former Dropbox employees — many women of color — alleged systemic gender disparities in pay, promotion, and treatment, in a report compiled by a former staff researcher that Dropbox strongly contested.
2020–2022
After Apple Silicon Macs shipped in late 2020, Dropbox went nearly a year without a native build, forcing its always-on sync daemon to run under Rosetta 2 emulation — to mounting user fury — before committing to a native release in 2022.
September 2021
On 30 September 2021 Dropbox stopped issuing the never-expiring access tokens many integrations relied on, switching to short-lived tokens plus refresh tokens — backups, scripts, and self-hosted tools that hard-coded a static token broke unless rewritten.
January–June 2021
Dropbox's own Transparency Report shows that a large share of the search warrants it receives arrive with indefinite non-disclosure orders, leaving the company unable to ever notify those users that the government took their data.
2020–2021
Italy's competition and consumer authority opened proceedings against Dropbox in 2020 over its cloud-storage terms; in 2021 it closed one case after Dropbox committed to clearer disclosures and, in a second, found several contract clauses unfair and ordered their removal — in both cases without a fine on Dropbox.
Dropbox replaced its coarse legacy access types with granular OAuth scopes, requiring every developer to revisit their app's permissions in the developer console and, in many cases, have existing users re-authorize before new functionality would work.
2013–2024
The DropSmack proof-of-concept warned that synced Dropbox folders could be a covert C2 and exfiltration channel; multiple real malware families — including BoxCaon, Crutch and tooling used by Kimsuky — went on to abuse Dropbox folders and the Dropbox API exactly that way.
In January 2021 Dropbox laid off about 315 employees — roughly 11% of its workforce — and announced the departure of its COO, framing the cuts as necessary to streamline the business even as the company was profitable and demand for remote tools was surging.
Topia Technology sued Dropbox and other cloud-storage companies over two file-synchronization patents; rather than fight in court, Dropbox and Box challenged the patents at the Patent Trial and Appeal Board, which found the claims unpatentable — a result later affirmed by the Federal Circuit.
2019–2026 (ongoing)
Users have long complained that Dropbox badgers them with upgrade prompts, full-page upsell interstitials, in-app badges, and marketing emails — pressure that hits not only free accounts but, by users' accounts, paying Professional customers too.
2020–2023
Dropbox went 'Virtual First' in 2020, making remote the default and converting offices to drop-in studios — but the shift, layered on a record 2017 San Francisco headquarters lease, drove hundreds of millions in real-estate impairment charges, including roughly $400M+ tied to subleasing its HQ.
October 2020
Dropbox made remote work its permanent default in 2020 and took significant real-estate impairment and restructuring charges as it closed and subleased offices.
2020 (Schrems II) onward
European courts and regulators treat data held by US providers as inherently reachable by US surveillance under FISA Section 702 and the CLOUD Act — a structural concern that applies to any US-controlled cloud service, including Dropbox, regardless of where servers sit.
June 2020
Dropbox launched a zero-knowledge password manager in 2020, but reviewers and privacy advocates questioned trusting a vault to a company that — for its core product — holds the encryption keys and has a documented history of breaches.
Launched September 2019; 'Spaces 2.0' beta late 2020; quietly retired
Dropbox launched 'Spaces' in 2019 as the new identity for its workspace app, relaunched it as 'Spaces 2.0' in a 2020 beta, and then quietly dropped the Spaces branding — the workspace ambitions folded back into the ordinary Dropbox app.
2020 onward
When the EU's top court struck down the EU–US Privacy Shield in 2020, Dropbox — which had self-certified under the framework — was among the US cloud services left exposed to European data-protection regulators questioning whether personal data could lawfully be transferred to the United States.
Express Mobile sued Dropbox along with eight other technology companies over website-builder patents in 2020; the suit against Dropbox was resolved by dismissal, consistent with a settlement, rather than a court ruling on the merits.
Dropbox's OAuth model historically let third-party apps request full account access, and tokens persist until revoked — so a single over-permissioned or compromised integration can read, write or delete a user's entire Dropbox without any further prompt.
July 2020
The EU's 2020 Schrems II ruling struck down the Privacy Shield framework over US surveillance, leaving EU organizations that store data with US providers like Dropbox needing extra safeguards — and unable to fully escape US legal reach.
Ongoing (long-standing)
Users complain that the Dropbox desktop app sets itself to launch at startup, embeds itself in Windows File Explorer and macOS Finder, and is difficult to fully remove — with 'failed to uninstall' errors and leftover launch agents, caches, and folders that must be cleaned out by hand.
2020 (introduced); ongoing
Apple's App Store privacy 'nutrition labels,' introduced in December 2020, require apps to disclose their data collection — and the Dropbox app's label lists a broad range of data linked to the user's identity, from contact info and identifiers to usage data and diagnostics.
Long-running, widely reported complaints describe the Dropbox desktop client consuming excessive CPU, disk, memory, and battery — sometimes pinning processors above 100% and draining laptop batteries even when nothing is actively syncing.
2013 launch; mobile Choosers later deprecated
Dropbox's 'Drop-ins' — the Chooser and Saver widgets that let any app use Dropbox as an open/save dialog — launched in 2013 with fanfare, but the iOS and Android Choosers were later deprecated and the program stagnated as Dropbox steered its platform away from third-party developers toward its own collaboration features.
September 2019
Anyone viewing a publicly shared Dropbox Paper document could see the full names and email addresses of every signed-in Dropbox user who had ever opened it — turning a collaboration feature into a personal-data harvesting tool.
Launched 2019 (limits ongoing)
Dropbox Transfer lets users send files via a link, but its meaningful size limits are gated by tier: free Basic and entry plans are capped at 2 GB per transfer, with the headline 100 GB (and 250 GB with a Replay add-on) reserved for higher-priced business tiers.
2019–2021
Patent-assertion entity SynKloud Technologies sued Dropbox in the Western District of Texas over patents on wireless-device access to remote storage; Dropbox's bid to move the case to California was denied, while SynKloud's broader patent campaign unraveled at the patent office.
June 2019
Dropbox's 2019 redesign replaced its famously minimal sync-folder app with a heavy, Electron-based 'workspace' window — a Slack-like file manager that critics said abandoned the simple, reliable syncing that made Dropbox loved.
Investors who bought stock tied to Dropbox's March 2018 IPO alleged the registration statement concealed a slowdown in converting free users to paying ones; after an initial dismissal, the case settled for $1.38 million with no admission of wrongdoing.
In June 2019 Dropbox doubled the Plus plan's storage from 1TB to 2TB but raised the price from roughly $9.99 to $11.99 per month, bundling in features many individual users did not want and giving them no way to keep the cheaper, smaller plan.
March 2019
Dropbox quietly restricted free Basic accounts to three linked devices in March 2019, a change discovered through updated help docs rather than an announcement, narrowing an already-thin 2GB free tier to push users toward paid plans.
In March 2019 Dropbox quietly capped free Basic accounts at three linked devices, a downgrade to a long-standing free tier designed to push users onto the $9.99-a-month Plus plan.
2008–2023
The referral program that powered Dropbox's early viral growth — once worth substantial free storage — was steadily devalued, and some long-time users reported referral-earned space being clawed back to the bare 2GB minimum.
August–November 2018
Dropbox announced that from November 2018 its Linux client would sync only on unencrypted ext4, abruptly breaking sync for users on XFS, Btrfs, ZFS, and encrypted volumes — including encrypted ext4.
March 2018
Dropbox's March 2018 IPO created a multi-class share structure concentrating voting power with co-founders Drew Houston and Arash Ferdowsi, limiting ordinary shareholders' say over the company's direction.
2012–2026
Dropbox's transparency reporting centers on US legal process, but as a global service it also faces foreign-government and cross-border demands — an area where its disclosures are thinner and the CLOUD Act blurs jurisdictional lines.
2017–2024
On the eve of Dropbox's 2018 IPO, CEO Drew Houston received a stock award reported at about $110 million for 2017 — a performance grant that could be worth up to roughly $930 million — even as the company would later cut thousands of jobs across 2021, 2023, and 2024.
July 2018
Dropbox gave Northwestern University researchers project-folder metadata covering some 16,000 scientists to study collaboration patterns. Users were never told their activity would be used for research, and academics warned the 'anonymized' data could re-identify individuals.
May 2018
Four California district attorneys accused Dropbox of violating the state's Automatic Renewal Law for its Dropbox Pro subscriptions; Dropbox settled for $2.15 million and agreed to change its renewal disclosures, without admitting liability.
November 2018
From 7 November 2018 Dropbox dropped sync support on Linux for every filesystem except unencrypted ext4, instantly breaking syncing for users on XFS, ZFS, ext3, Btrfs, and encrypted setups — making their data unavailable through Dropbox overnight.
The 2018 CLOUD Act amended US law so that a US-based provider like Dropbox can be compelled to produce a user's data regardless of which country the data is physically stored in — meaning a US warrant can reach an overseas user's files.
August 2018 (enforced November 2018)
Dropbox told Linux users that from November 2018 its client would sync only on unencrypted ext4, abruptly stripping support for XFS, Btrfs, ZFS, and encrypted setups — communicated as a terse desktop notification with little explanation.
2017–2018 onward
Linux users found Dropbox's system-tray icon — their primary way to see sync status and open the menu — broken or missing as desktops moved away from legacy tray icons toward AppIndicator, leaving Dropbox's status menu unreliable across popular distributions.
2017
Dropbox's Smart Sync (formerly Project Infinite) let files appear in the file manager without being downloaded — convenient, but a recurring source of confusion when 'online-only' files were unavailable offline or seemingly vanished.
Project Infinite announced April 2016; launched as Smart Sync January 2017
Dropbox demoed 'Project Infinite' in 2016 as a way to see all cloud files on the desktop without using disk space, then shipped it in January 2017 rebranded as 'Smart Sync' — but restricted it to paying Business and Professional tiers rather than the free product its demo had implied.
2017 (links disabled September 2017)
Dropbox converted the long-standing Public folder into an ordinary private folder and then disabled all of its public links on 1 September 2017, breaking countless URLs people had embedded across the web with no automatic migration.
2017 onward
Dropbox's Smart Sync feature, meant to keep files 'online-only' to free local disk space, has repeatedly failed in the opposite direction — quietly re-downloading online-only files and filling up users' drives, or reverting their carefully chosen local/online states.
2016 deprecation, shut down September 2017
Dropbox deprecated its original API v1 in 2016 and shut it off on 28 September 2017, forcing every third-party developer to rewrite for the incompatible v2 or watch their Dropbox integration stop working.
January 2017
In January 2017 files and folders that users had deleted — in some cases as far back as 2009 — suddenly reappeared in their accounts, revealing that 'deleted' data had been retained on Dropbox's servers far longer than its own policy promised.
August 2016
Four years after the 2012 breach, the stolen credentials surfaced in the wild, forcing Dropbox to reset the passwords of all users who had not changed them since mid-2012.
2016 onward
Before Dropbox acquired HelloSign in 2019, a patent-assertion entity called Digital Verification Systems had sued HelloSign over an electronic-signature patent — one of a wave of near-identical suits — leaving Dropbox to inherit the dispute along with the company.
December 2015 (shut down March 2016)
Dropbox launched Carousel as a dedicated photo-and-video gallery app in 2014, then announced its closure barely 18 months later, shutting it down on 31 March 2016.
A persistent class of complaints describes Dropbox files that sit indefinitely in a 'syncing' state and never finish, leaving users unsure whether their data was actually uploaded — in some reported cases for months, with support unable to resolve it.
2016–2021
Synchronoss Technologies accused Dropbox of infringing three data-synchronization patents; Dropbox won summary judgment of non-infringement and invalidity in 2019, and the Federal Circuit affirmed in 2021.
September 2016
Researchers revealed that Dropbox's Mac client used a user's admin password to directly edit macOS's protected TCC.db permissions database, inserting itself into the Accessibility list — a privacy/trust list that grants near-total control over the machine — without a clear, informed prompt.
When the full 2012 credential dump resurfaced in 2016, Dropbox forced a password reset on every user who had signed up before mid-2012 and never changed their password — a sweeping operational response that, for many, was the first sign anything was wrong.
2015–2017
Dropbox's move from the v1 Core API to API v2 was not a drop-in upgrade: error handling, authentication, permissions, and request formats all changed, forcing developers to rewrite integrations before v1 was switched off in 2017.
2016
After a review of the cloud-storage sector, the UK's Competition and Markets Authority secured voluntary commitments from providers including Dropbox in 2016 to improve unfair contract terms — covering notice of price and service changes, cancellation and refunds, and auto-renewal transparency.
2011–2026
Because Dropbox holds the keys to decrypt users' files, a valid legal order doesn't just get a government encrypted data it can't read — it gets readable file content. The design choice is what makes lawful compulsion effective.
2015 (ongoing practice)
Dropbox runs every uploaded image and video through hash-matching systems such as Microsoft's PhotoDNA to detect known child sexual abuse material — automated scanning of users' private files that the company initially refused to explain.
Names that are distinct on Dropbox's case-sensitive, Unicode-tolerant servers but identical on Windows or macOS collide on sync, and Dropbox resolves the clash by silently appending '(Case Conflict)' or '(Unicode Encoding Conflict)' to one of the files.
2014–2018
Thru Inc. claimed it had used the term 'Dropbox' since 2004 and threatened the company's trademark; Dropbox sued first for declaratory relief, won summary judgment, and the Ninth Circuit affirmed — with a roughly $2.3 million attorneys'-fee award against Thru.
December 2015 (shut down February 2016)
Dropbox paused all development and then killed Mailbox, the gesture-driven email app it had acquired in 2013 to enormous fanfare, telling devoted users to find a new client by 26 February 2016.
August 2015
At Black Hat USA 2015, Imperva researchers showed that stealing a single synchronization token let an attacker take over a Dropbox account and read its files indefinitely — and that, in Dropbox's case, changing the password did not revoke the stolen token.
April 2015 (Sync deprecated Oct 2015, Datastore shut April 2016)
In April 2015 Dropbox announced it would retire the Sync API and the Datastore API, giving developers about a year to rewrite onto the Core API — apps that did not migrate stopped working when the Datastore API was shut down on 29 April 2016.
To comply with US trade sanctions and embargoes, Dropbox does not provide service in regions such as Crimea, North Korea, and Syria — meaning users there can be cut off from their existing files by their provider's home-country law.
On 30 August 2015 Dropbox suffered a worldwide outage that locked users out of their files; the company blamed an issue that arose during routine internal maintenance.
2015
During the August 2015 global outage, Dropbox's status page reported service restored while many users were still locked out — a documented gap between the company's stated status and the actual experience of its users.
November 2014
Responding to criticism of Dropbox's lack of zero-knowledge encryption, CEO Drew Houston framed the fact that Dropbox can access users' files as a deliberate 'trade-off between usability/convenience and security.'
April–July 2014
Dropbox's April 2014 appointment of former Secretary of State Condoleezza Rice — a defender of warrantless wiretapping — to its board triggered the grassroots 'Drop Dropbox' campaign, and months later Edward Snowden publicly branded the service 'hostile to privacy.'
China's Great Firewall has blocked Dropbox since 2014 — at one point cutting users off from their own files overnight without warning — leaving the service reachable in the country only via VPNs that are themselves restricted.
March 2014
A viral 2014 incident revealed that Dropbox compares the cryptographic hashes of files users try to share against a blacklist of DMCA-flagged content and blocks matches — surprising users who assumed their files were entirely private.
Because Dropbox mirrors a permissive server namespace onto stricter local filesystems, files with disallowed characters, over-long paths, or trailing periods can fail to sync or be silently renamed — sometimes without any clear warning to the user.
2014–2015
Years before the California district attorneys' 2018 settlement, a private plaintiff brought a class action alleging Dropbox enrolled users in automatic subscription renewals without proper consent under California's Automatic Renewal Law; the case was removed to federal court and ended in a stipulated dismissal.
2014–present
After the 2013 PRISM disclosures named major US tech firms, Dropbox spent the following years documenting — through its own reports and advocacy — that it sits inside the same surveillance ecosystem: subject to NSLs, FISA orders and rising law-enforcement demands, with only banded, gagged disclosure permitted.
2013–present
Because gag orders bar providers from confirming secret national-security demands, some companies post a 'warrant canary' — a standing statement that disappears if such a demand arrives. Dropbox relies on banded transparency reporting rather than a canary, leaving the most sensitive demands invisible to users.
2013–2026
When Dropbox cannot reconcile two versions of a file, it preserves both — saving the loser as a duplicate stamped 'conflicted copy' — a data-safety mechanism that in practice creates lasting duplication and version confusion that users cannot turn off.
October 2014
Hackers claimed to have stolen nearly 7 million Dropbox logins, posted batches on Pastebin, and demanded Bitcoin — but the credentials came from other breached services, not Dropbox itself.
As thousands of intercepted Snapchat photos leaked in the so-called 'Snappening,' early reports tied Dropbox to the incident — but Dropbox flatly denied any involvement, and the actual leaks came from third-party apps and unrelated breaches, not Dropbox's systems.
2014
A flaw in Dropbox's desktop Selective Sync feature permanently destroyed the files of users whose client crashed or was force-quit mid-operation — including one photographer who lost more than 8,000 irreplaceable images. Dropbox compensated affected users with a year of Dropbox Pro.
May 2014
Researchers found that Dropbox's shared links to supposedly private documents could leak to third parties — exposed through browser referer headers and, in some cases, surfacing in Google search results — revealing tax returns, bank records, and business plans.
January 2014
A subtle bug in a maintenance script reinstalled the operating system on a small number of active production database machines, knocking Dropbox offline starting Friday 10 January 2014, with full service not restored until Sunday.
On 10–11 January 2014 Dropbox went dark for roughly two hours after an internal maintenance error, while a group calling itself 1775 Sec falsely claimed to have breached it — a hoax that briefly stoked panic about user data.
2013
At Black Hat Europe 2013, a researcher demonstrated 'DropSmack,' a technique that abused Dropbox sync to slip malware past corporate firewalls and quietly exfiltrate company files.
August 2013
At USENIX WOOT 2013, Dhiru Kholia and Przemyslaw Wegrzyn unpacked and decompiled Dropbox's obfuscated-Python desktop client, demonstrated SSL interception via code injection, and described a way to hijack accounts and bypass two-factor authentication.
June 2013
Among the classified NSA PRISM documents leaked by Edward Snowden, Dropbox appeared as a provider the surveillance program planned to add, listed as 'coming soon' — placing the company squarely inside the post-Snowden surveillance debate.
2013–2014
Dropbox is subject to National Security Letters and FISA orders that arrive with gag provisions barring it from disclosing even that it received them; the most it can publish is a band such as '0–249' national-security requests.
July 2013
Q-CERT researchers found that because Dropbox did not verify email addresses at signup, an attacker who already had a victim's password could register a near-duplicate email, enable 2FA on it, and use the resulting emergency code to switch off the real account's two-step verification.
2012–present
Dropbox has published a biannual Transparency Report since 2012, and its own figures document a steady, long-run climb in government and law-enforcement demands for user data — including reporting periods where US legal-process requests jumped by roughly a third.
2012 (disclosed in full 2016)
An attacker used a Dropbox employee's reused password to steal a file containing roughly 68 million users' email addresses and hashed passwords — a theft whose full scale only became public in 2016.
April 2011
Researcher Derek Newton showed that Dropbox's desktop client stored an unencrypted authentication token (host_id) in a local config.db file — copy that one value to another machine and you owned the victim's account, with no password and no notification.
July 2011
A July 2011 terms-of-service and privacy-policy update used broad licensing language that many users read as Dropbox asserting ownership-like rights over their files, forcing the company to publicly clarify and walk back the wording.
2011
Dropbox splits files into blocks, hashes each with SHA-256, and stores only one copy of any block it already holds — a cost-saving design that researcher Christopher Soghoian warned could leak whether a given file already exists on Dropbox's servers.
2011–2026 (ongoing)
Dropbox encrypts files at rest, but the encryption keys belong to Dropbox, not the user. This server-side model — chosen to enable deduplication, previews, and search — means the company can read user files, the root cause critics return to again and again.
May 2011
Security researcher Christopher Soghoian filed a complaint with the U.S. Federal Trade Commission alleging that Dropbox made deceptive claims about its encryption, because Dropbox employees could in fact access users' files.
April–May 2011
Security researcher Christopher Soghoian filed an FTC complaint alleging Dropbox had told users their files were inaccessible even to Dropbox employees, while its actual architecture — and a quietly revised Terms of Service — made clear the company could decrypt and hand over files.
June 2011
For nearly four hours on 19 June 2011, a code update left Dropbox accounts accessible with any password at all — anyone could sign in to any account by typing anything.
Days after Dropbox disclosed the June 2011 bug that briefly let anyone sign into any account with any password, a plaintiff filed a class action alleging privacy and consumer-protection violations; the case was terminated within four months.
2001 onward
The 2001 USA PATRIOT Act expanded US government access to records held by domestic companies and became the original reason foreign organizations distrusted storing data with US cloud providers — a concern that still attaches to Dropbox today.
1986 (governs Dropbox today)
Under the 1986 Stored Communications Act, US law enforcement can obtain a Dropbox user's basic subscriber records with a subpoena, account usage records with a court order, and the actual contents of their files with a search warrant — a tiered framework Dropbox publishes in its own guidelines.