Data breach
Dropbox
- Records
- 87,294,301
- Breach date
- 1 July 2012Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses87,294,301
- Passwords10,281,747
About this breach
Dropbox's investigation team has indexed roughly 87.3 million records tied to the long-running 2012 Dropbox breach, including about 10.3 million rows that also contain password data, alongside email addresses for every row in the set. The listing carries no claimed threat actor and no ransom demand. The breach itself became public in a very different form than the index: in August 2016, Dropbox forced password resets after learning that a circulating database of user email addresses and hashed passwords, believed stolen in 2012, was genuine. Contemporary reporting, including BBC News, put the confirmed list at roughly 68 million accounts, meaning the files circulating among criminals covered fewer accounts than our team has indexed, which is consistent with a dataset that grew or merged over time.
Breach Timeline
Mid-2012: Dropbox disclosed an incident in which an employee's reused password led to unauthorized access to a company document containing user email addresses.
August 2016: Dropbox announced a forced password reset for any account whose password had not been changed since mid-2012, describing it as a preventive measure.
Late August 2016: Security researchers and news outlets confirmed a database of about 68.6 million Dropbox email addresses and hashed passwords circulating online was legitimate.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords, with email addresses present in all 87,294,301 indexed rows and password fields present in 10,281,747 of them.
Dropbox described the credential set as email addresses paired with hashed and salted passwords, not plaintext passwords. Reporting at the time of the 2016 disclosure noted the passwords used two hashing methods, with roughly half protected by bcrypt and the rest by the older SHA-1 algorithm, both salted. SecurityWeek reported that bcrypt hashes are very resistant to cracking, while the SHA-1 portion faced somewhat greater risk.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The clearest immediate risk in 2016 was that cracked passwords could be tried against other services. People who reused their Dropbox password elsewhere faced the greatest danger, since attackers regularly test leaked credentials against email, banking, and social media logins. This breach is also a textbook example of why that risk exists: reporting by Business Insider traced the original intrusion to a Dropbox employee who had reused a password exposed in another site's breach.
Even years later, email addresses in a known-good list remain useful to criminals for phishing. Messages that cite an old, real breach tend to look more convincing than generic spam, and some may urge recipients to visit a fake Dropbox login page.
What Is Dropbox Doing in Response?
Dropbox's response centered on the 2016 password reset. The company said it learned of the circulating credentials about two weeks before its announcement, emailed users it believed were affected, and reset passwords for anyone who had not changed theirs since mid-2012. In a statement reported by the BBC, Dropbox said the reset meant the credentials could not be used to access Dropbox accounts even if the hashes were cracked, and that it had no indication accounts had been improperly accessed. The company also recommended unique passwords and two-step verification. We have not found a more recent operator statement specific to this listing as of the date of this article.
What Should You Do If You Were Affected?
If your Dropbox password has not been changed since before mid-2016, change it now, even after all this time.
If you ever reused a password on other accounts, change it everywhere. Use a different password for each service.
Turn on two-factor authentication for Dropbox and your email account.
Watch for phishing emails that mention Dropbox or data breaches, and avoid clicking login links in unexpected messages.
A password manager makes unique passwords practical at scale.
In the news
- BBC News, "Dropbox hack 'affected 68 million users'"bbc.com (opens in a new tab)
- Deutsche Welle, "Dropbox confirms millions of user data stolen"dw.com (opens in a new tab)
- Sophos News, "Dropbox hack leads to 68 million password hashes dumped online"news.sophos.com (opens in a new tab)
- SecurityWeek, "68 Million Exposed in Old Dropbox Hack"securityweek.com (opens in a new tab)
- Business Insider, "Hackers stole almost 70 million customer passwords from Dropbox"businessinsider.com
