DROPBOX, INC.
ent_019de1dbbe0c0b2b0eeea3087cb88274
Disclosures
2
SEC 10-K Item 1C · SEC 8-K · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DROPBOX, INC.
- Normalized
- dropbox— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JCDF7UAR6TJR51
- SEC EDGAR CIK
- 0001467623
- Domain
- dropbox.com
Disclosure history (2)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-20
Dropbox, Inc. (ticker: DBX) filed its 2024 Form 10-K with Item 1C disclosing its cybersecurity risk management and governance framework. The filing details internal controls including vulnerability management, red teaming, and incident response. No specific cybersecurity incident, breach, or material financial impact is reported in this filing.
- FEDERALSEC 8-Kas victim2024-05-01
On April 24, 2024, Dropbox discovered unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The threat actor accessed data of all Dropbox Sign users, including emails, usernames, and account settings, and for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA information. No evidence of access to account contents or payment information. Incident appears limited to Dropbox Sign infrastructure. Investigation, law enforcement, and regulator notifications ongoing.