Dropbox
Disclosed Jul 31, 201214 years ago68,648,009 affectedConfirmed
Stolen employee password leads to Dropbox user email theft; 68M credentials later leak
Dropbox said usernames and passwords stolen from other sites were used to sign in to some accounts, including an employee account holding a project document with user emails. In 2016 a dump of 68.6 million Dropbox credentials from 2012 surfaced.
What is known
| People affected | 68,648,009 (as reported by the organization) |
|---|---|
| Disclosed | Jul 31, 2012 |
| Happened | Jul 1, 2012 |
| Attack | Credential stuffing |
| Data exposed | Emails, Passwords |
| Sector | Tech · US |
| Status | Confirmed |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Dropboxhaveibeenpwned.com · Aggregator | Aggregator |
| Security update and new featuresblog.dropbox.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jul 31, 2012 | 68,648,009 |
| Have I Been Pwnedaccounts in the data | Aug 31, 2016 | 68,648,009 |
Other breaches at Dropbox
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Lenovo ID verification flaw let attacker access about 5,000 Dropbox accountsSep 23 weeks agoVendor breachUnverified | Sep 23 weeks ago | Vendor breach | Tech | Unverified | 5,000 |
| Material cybersecurity incident reported to the SEC (8-K Item 1.05)May 1, 20242 years ago | May 1, 20242 years ago | Not stated | Tech | Confirmed | Unknown |
| Phishing attack lets hacker steal 130 Dropbox GitHub repositoriesNov 1, 20223 years agoPhishingUnverified | Nov 1, 20223 years ago | Phishing | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · source_type: aggregator to company · seed source
- 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/Dropbox to https://blog.dropbox.com/topics/company/security-update-new-features · seed source
- 2026-09-25 · status: disclosed to confirmed · seed source
- 2026-09-25 · verified_by: empty to research · seed source
- 2026-09-25 · verified: 0 to 1 · seed source
- 2026-09-25 · country: empty to US · seed source
- 2026-09-25 · attack: unknown to credential-stuffing · seed source
- 2026-09-25 · records_basis: hibp to organization · seed source
- 2026-09-25 · disclosed: 2016-08-31 to 2012-07-31 · seed source
- 2026-09-25 · summary: In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk . A large volume of data totalli to Dropbox said usernames and passwords stolen from other sites were used to sign in to some accounts, including an employee account holding a project document with user emails. In 2016 a dump of 68.6 million Dropbox credentials from 2012 surf · seed source
- 2026-09-25 · title: empty to Stolen employee password leads to Dropbox user email theft; 68M credentials later leak · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned), confirmed by Research. Record counts are as reported. Not legal advice.