Back to Blog

The Dropbox Breach: How 68 Million Accounts Were Exposed for Four Years

LeakedSource Team
|

A Breach That Grew With Time

In mid-2012, Dropbox disclosed what it described as a limited security incident. Users reported receiving spam at email addresses they had only used for Dropbox, and the company acknowledged that a stolen employee password had been used to access a project document containing user email addresses. At the time, the public understanding was that only email addresses had been exposed.

Four years later, in August 2016, the true scale emerged. A database containing approximately 68.7 million Dropbox account credentials appeared on dark web marketplaces and was verified as authentic. The records included email addresses and hashed passwords, revealing that the original 2012 breach had been far more severe than initially reported.

How the Breach Happened

The attack chain was straightforward and relied on a single point of failure: credential reuse. A Dropbox employee had used the same password on both LinkedIn and Dropbox's internal systems. When LinkedIn suffered its own breach in 2012, attackers harvested that reused credential and used it to access Dropbox's corporate network.

Once inside, the attackers gained access to a user database containing:

  • 68.7 million email addresses
  • Hashed passwords using a mix of bcrypt and SHA-1
  • Salt values for the hashed passwords

The use of bcrypt for a significant portion of the passwords provided meaningful protection, as bcrypt is computationally expensive to crack. However, a subset of passwords had been hashed with SHA-1, which is far more vulnerable to brute-force attacks.

The Four-Year Gap

The delay between the 2012 incident and the 2016 disclosure of the full dataset raises important questions about breach detection and transparency. During those four years, the stolen credentials were presumably circulating among a smaller group of attackers before eventually reaching wider distribution.

Dropbox had taken some precautionary steps after the initial 2012 disclosure, including forcing password resets for accounts created before mid-2012. However, the company did not fully understand or publicly communicate the extent of the data loss until the database surfaced publicly in 2016.

This timeline illustrates a recurring pattern in major breaches: the true scope of an incident often takes months or years to become apparent. Organizations may genuinely not know what was taken, or they may underestimate the severity based on incomplete forensic analysis.

Lessons From the Dropbox Breach

Credential reuse is an organizational risk, not just a personal one. The breach began because an employee reused a password across services. Organizations that do not enforce unique credentials for corporate systems inherit the security posture of every external service their employees use.

Password hashing algorithms matter. The accounts protected by bcrypt proved substantially harder to crack than those using SHA-1. The choice of hashing algorithm directly determines how useful a stolen database is to attackers.

Breach scope can expand over time. Initial assessments often undercount the damage. Companies should plan for the possibility that early incident reports will prove optimistic and build their response plans accordingly.

Proactive password resets save accounts. Dropbox's decision to reset passwords for older accounts in 2012 likely protected many users even before the full breach was understood. When in doubt, forcing a credential rotation is a defensible choice.

What Dropbox Changed

Following the full disclosure in 2016, Dropbox accelerated several security improvements:

  • Mandatory password resets for all accounts that had not changed their password since 2012
  • Support for hardware security keys and TOTP-based two-factor authentication
  • Migration to bcrypt for all remaining password hashes
  • Bug bounty program expansion to incentivize external security research

These changes reflected industry best practices that have since become standard expectations for cloud storage providers.

Protecting Yourself After Historical Breaches

Even years after a breach, exposed credentials remain dangerous if passwords were reused across services. If you used Dropbox before 2013, you should assume your email and password hash were compromised and take the following steps:

  • Change passwords on any service where you used the same credentials as your old Dropbox account
  • Enable two-factor authentication on Dropbox and every other service that supports it
  • Use a password manager to generate and store unique passwords for every account
  • Monitor your email address for appearances in new breach datasets

Check LeakedSource to see whether your email address appears in the Dropbox breach or any other known data exposure.

Check Your Breach Exposure

Find out if your email address has been compromised in any known data breaches.

Scan Your Email Now

LeakedSource Support

AI assistant — a human reviews escalated chats

This chat has been escalated to our support team — a human will reply here or by email. If you haven't shared your email yet, just type it here so we can reach you.
Hi! I'm the LeakedSource assistant. Ask me about scans, breaches, billing, or your account.