DROPBOX, INC.
ent_019de1dbbe0c0b2b0eeea3087cb88274
Disclosures
2
State AG · SEC 8-K · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,724
as filed · State AG SC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DROPBOX, INC.
- Normalized
- dropbox— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JCDF7UAR6TJR51
- SEC EDGAR CIK
- 0001467623
- Domain
- dropbox.com
Disclosure history (2)newest first
- South Carolina State AGas victim2024-06-04
Dropbox, Inc. reported unauthorized access to its Dropbox Sign (formerly HelloSign) production environment on April 24, 2024. A threat actor compromised a service account to access customer data including email addresses, usernames, phone numbers, hashed passwords, and authentication tokens. The incident was isolated to Dropbox Sign. Dropbox engaged forensic investigators, reset passwords, and notified regulators.
- FEDERALSEC 8-Kas victim2024-05-01
On April 24, 2024, Dropbox discovered unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The threat actor accessed data of all Dropbox Sign users, including emails, usernames, and account settings, and for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA information. No evidence of access to account contents or payment information. Incident appears limited to Dropbox Sign infrastructure. Investigation, law enforcement, and regulator notifications ongoing.