On April 24, 2024, Dropbox discovered unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The threat actor accessed data of all Dropbox Sign users, including emails, usernames, and account settings, and for subsets of users, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA information. No evidence of access to account contents or payment information. Incident appears limited to Dropbox Sign infrastructure. Investigation, law enforcement, and regulator notifications ongoing.