DROPBOX, INC.
bd_26d346e70b299689 · schema v1 · pii pii-v1
Full breach record for DROPBOX, INC. →On April 24, 2024, Dropbox discovered unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The threat actor accessed data of all Dropbox Sign users, including emails, usernames, and account settings, and for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA information. No evidence of access to account contents or payment information. Incident appears limited to Dropbox Sign infrastructure. Investigation, law enforcement, and regulator notifications ongoing.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 24, 2024
Discovered
Apr 29, 2024
Scope determined
May 1, 2024
Filed
vs. sector median
18 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- South Carolina State AGbd_7f7953060df2db902024-06-04 · +34dVerified
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing May 1, last Jun 4 (SC) — a 34-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.