DROPBOX, INC.
bd_7f7953060df2db90 · schema v1 · pii pii-v1
Full breach record for DROPBOX, INC. →Dropbox, Inc. reported unauthorized access to its Dropbox Sign (formerly HelloSign) production environment on April 24, 2024. A threat actor compromised a service account to access customer data including email addresses, usernames, phone numbers, hashed passwords, and authentication tokens. The incident was isolated to Dropbox Sign. Dropbox engaged forensic investigators, reset passwords, and notified regulators.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 24, 2024
Discovered
Jun 4, 2024
Filed
vs. sector median
13 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- SEC 8-Kbd_26d346e70b2996892024-05-01 · +34dCandidate
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing May 1, last Jun 4 (SC) — a 34-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.