Skip to content

Dropbox Sign

Disclosed May 1, 20242 years agoConfirmed

SEC filing

Threat actor accesses Dropbox Sign production environment and all user data

Dropbox said it became aware on April 24, 2024 of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The actor accessed emails, usernames and account settings for all Dropbox Sign users and, for subsets of users, phone numbers, hashed passwords and authentication information such as API keys and OAuth tokens.

What is known

People affectedNot stated in the sources we have
DisclosedMay 1, 2024
DiscoveredApr 24, 2024
AttackHacking
Data exposedEmails, Names, Phone numbers, Passwords, API keys, Credentials and tokens
SectorTech · US
StatusConfirmed

Sources

Source
Dropbox Form 8-K (May 1, 2024)sec.gov · SEC filing

Notices filed

WhereFiledPeople
ResearchtotalMay 1, 2024
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Dropbox Sign

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.