Dropbox wasn't hacked
Recent news articles claiming that Dropbox was hacked aren't true. Your stuff is safe. The usernames and passwords referenced in these articles were stolen from unrelated services, not Dropbox. Attackers then used these stolen credentials to try to log in to sites across the internet, including Dropbox.
The Dropbox Blog Anton Mityagin
Context & Ripple Effects
Dropbox's blog post is a direct rebuttal to a story cycle that began the day before, when The Next Web reported Dropbox denying an alleged 7-million-account hack and attributing the leaked logins to expired credentials stolen from third-party services. The pickup was unusually broad — TIME, Business Insider, The Hill, eWeek and PandoDaily all carried the denial within a day — which is precisely why Dropbox escalated to its own blog rather than leaving it to press queries.
The denial lands against a longer security history at the company: in July 2012 Dropbox disclosed that user accounts were hijacked and added new security features, days after a spam wave pointed at a possible leak of user email addresses. That record makes the 'wasn't hacked' framing load-bearing for a company simultaneously pushing consumer partnerships like the Samsung Galaxy Note 4 and Sony Xperia Z3 integrations reported earlier this month.
First-order effects
- Users whose passwords were reused across sites are the actual victims here — attackers held valid email-password pairs and ran them against Dropbox logins, so accounts protected only by a shared password are exposed right now regardless of where the leak originated.
- Dropbox's own channels, not the press, become the trust-repair surface: the company has to convert an 'attackers tried these credentials everywhere' story into user confidence while its partnerships team courts device makers.
Second-order effects
- Every consumer web service faces the same replayed-credential traffic from whatever breach produced these lists, forcing the industry-wide question of mandatory second factors and password resets rather than per-company fixes.
- Security reporters gain a template they will reuse — 'X million credentials dumped online' headlines arrive before any attribution — meaning vendors now need same-day forensic denial capability as a communications function.
Third-order effects
- If credential dumps from one breached service keep getting weaponized against every other service, accountability shifts from 'who got hacked' to 'who let password reuse persist' — pushing authentication design toward factors that don't depend on secret strings users repeat.
- Cloud storage providers competing for enterprise and OEM deals (as Dropbox is with Samsung and Sony) will find that breach perception, even when denied, prices into those negotiations alongside the actual security posture.
The trend: Cloud services are entering an era where their security reputation is set less by their own breaches than by other companies' leaks being replayed against their logins, making rapid attribution and denial part of the product.
Related: Dropbox · Dropbox denies alleged 7M account hack · Dropbox Reports User Accounts Were Hijacked · Dropbox Users Targeted By Spam
Related Coverage
- Dropbox denies alleged 7M account hack, says expired logins were stolen from third-party services The Next Web · Owen Williams
- eWeek eWeek · Sean Michael Kerner
- PandoDaily PandoDaily · Nathaniel Mott
- The Hill The Hill · Mario Trujillo
- Business Insider Business Insider · James Cook
- Inquirer Inquirer · Chris Merriman
- TIME TIME · Sam Frizell
- theWHIR.com theWHIR.com · Chris Burt
- Cult of Mac Cult of Mac · Alex Heath
- PCMag Australia Feed PCMag Australia Feed · Fahmida Y. Rashid
- Guardian Guardian · Samuel Gibbs
- bizjournals bizjournals · Cromwell Schubarth
- ZDNet ZDNet · Chris Duckett
- blog.chron.com blog.chron.com · Dwight Silverman
- iPhone iPhone · J.R. Bookwalter
- Help Net Security Help Net Security
- iPhone Hacks iPhone Hacks · Gautam Prabhu
- memeburn memeburn · Jacques Coetzee
- Geeky Gadgets Geeky Gadgets · Roland Hutchinson
- iMore iMore · Harish Jonnalagadda
- BetaNews BetaNews · Ian Barker
- Gigaom Gigaom · David Meyer
- Engadget Engadget · Mariella Moon
- TechnoBuffalo TechnoBuffalo · Killian Bell
- KitGuru KitGuru · Matthew Wilson
- BuzzFeed BuzzFeed · Matthew Lynley
- Techly Techly · Tristan Rayner
- 9to5Mac 9to5Mac · Mike Beasley
- cloudcomputing-news.net cloudcomputing-news.net · James
- SecurityWeek SecurityWeek · Eduard Kovacs
- App Advice App Advice · Aldrin Calimlim
- PC Pro PC Pro · Jane McCallion
- bit-tech.net bit-tech.net · Gareth Halfacree
- @marcoarment @marcoarment · Marco Arment
- @bobegan @bobegan · Bob Egan
- @ourielohayon @ourielohayon · Ouriel Ohayon
- @cultofmac @cultofmac · Cult of Mac
- @drpizza @drpizza · Peter Bright
- Pastebin Pastebin
- The Register The Register · Darren Pauli
- Digital Trends Digital Trends · Trevor Mogg
- Ars Technica Ars Technica · Peter Bright
- Reuters Reuters · Supriya Kurane
- GadgeTell GadgeTell · Seth Fitzgerald
- CNET CNET · Claire Reilly
- Neowin Neowin · Brad Sams
- Gotta Be Mobile Gotta Be Mobile · Josh Smith
- BGR BGR · Chris Smith
- ITProPortal ITProPortal · Barclay Ballard
- AppleInsider AppleInsider
- Mashable Mashable · Jenni Ryall
- SlashGear SlashGear · JC Torres
- VatorNews VatorNews · Steven Loeb
- TechCrunch TechCrunch · Natasha Lomas
- Ubergizmo Ubergizmo · Tyler Lee
- ReadWrite ReadWrite · Adriana Lee
- Yahoo Tech Yahoo Tech · Alyssa Bereznak
- Technology Personalized Technology Personalized · Raju PP
- Gizmodo Australia Gizmodo Australia · Luke Hopewell
- Gizmodo Gizmodo · Ashley Feinberg
- Lifehacker Lifehacker · Whitson Gordon
- VentureBeat VentureBeat · Dylan Tweney
- WebProNews WebProNews · Chris Crum
- Electronista Electronista
- @ow @ow · Owen Williams
- @swiftonsecurity @swiftonsecurity · InfoSec Taylor Swift
- @bdsams @bdsams · Brad Sams
- @obinkhorst @obinkhorst · Oliver Binkhorst
- View article eWeek
- View article PandoDaily
- View article The Hill
- View article Business Insider
- View article Inquirer
- View article TIME
- View article theWHIR.com
- View article Cult of Mac
- View article PCMag Australia Feed
- View article Guardian
- View article bizjournals
- View article ZDNet
- View article blog.chron.com
- View article iPhone
- View article Help Net Security
- View article iPhone Hacks
- View article memeburn
- View article Geeky Gadgets
- View article iMore
- View article BetaNews
- View article Gigaom
- View article Engadget
- View article TechnoBuffalo
- View article KitGuru
- View article BuzzFeed
- View article Techly
- View article 9to5Mac
- View article cloudcomputing-news.net
- View article SecurityWeek
- View article App Advice
- View article PC Pro
- View article bit-tech.net
- View article @marcoarment
- View article @bobegan
- View article @ourielohayon
- View article @cultofmac
- View article @drpizza
- View article Pastebin
- View article The Register
- View article Digital Trends
- View article Ars Technica
- View article Business Insider
- View article Reuters
- View article GadgeTell
- View article CNET
- View article Neowin
- View article Gotta Be Mobile
- View article BGR
- View article ITProPortal
- View article AppleInsider
- View article Mashable
- View article SlashGear
- View article VatorNews
- View article TechCrunch
- View article Ubergizmo
- View article ReadWrite
- View article Yahoo Tech
- View article Technology Personalized
- View article Gizmodo Australia
- View article Gizmodo
- View article Lifehacker
- View article VentureBeat
- View article WebProNews
- View article Electronista
- View article @ow
- View article @swiftonsecurity
- View article @swiftonsecurity
- View article @bdsams
- View article @swiftonsecurity
- View article @obinkhorst