Dropbox Sign
Disclosed May 1, 20242 years agoConfirmed
Threat actor accesses Dropbox Sign production environment and all user data
Dropbox said it became aware on April 24, 2024 of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. The actor accessed emails, usernames and account settings for all Dropbox Sign users and, for subsets of users, phone numbers, hashed passwords and authentication information such as API keys and OAuth tokens.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | May 1, 2024 |
| Discovered | Apr 24, 2024 |
| Attack | Hacking |
| Data exposed | Emails, Names, Phone numbers, Passwords, API keys, Credentials and tokens |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Dropbox Form 8-K (May 1, 2024)sec.gov · SEC filing | SEC filing |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | May 1, 2024 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.