FEDERALItem 1.05 · mandatoryHackingTechnologyInformationSoftwareCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICCREDENTIALSAUTHENTICATIONLowActive
DROPBOX, INC.
bd_26d346e70b299689 · schema v1 · pii pii-v1
Full breach record for DROPBOX, INC. →On April 24, 2024, Dropbox discovered unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The threat actor accessed data of all Dropbox Sign users, including emails, usernames, and account settings, and for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA information. No evidence of access to account contents or payment information. Incident appears limited to Dropbox Sign infrastructure. Investigation, law enforcement, and regulator notifications ongoing.
SEC clockMateriality determined Apr 29, 2024 → Filed May 1, 20242d ✓ SEC 4-day OK7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1467623/000146762324000024/dbx-20240429.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 1, 2024
- Raw hash
- e7803a53c8dc123e1026dbaf0f121c659d6a656841ae9fb7dfcf314b879bfa18
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- DROPBOX, INC.norm: dropbox
- SEC CIK
- 0001467623
- Domain
- dropbox.com
Victim entity
- Name
- DROPBOX, INC.norm: dropbox
- SEC CIK
- 0001467623
- Domain
- dropbox.com
- Industry
- Technology - Software / Cloud Storage
- Industry
- TechnologyllmNAICS 513210 · Software Publishers
Incident
- Discovered
- Apr 24, 2024
- Materiality determined
- Apr 29, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALSAUTHENTICATION
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- External
- Regulator citations
- Notifying regulatory authoritiesFiled 8-K Item 1.05 with the SEC
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Apr 29, 2024→ Filed: May 1, 20242d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.