Skip to main content

Company intelligence

Dropbox cybersecurity incidents and threat signals

dropbox.com

Dropbox logo

This company page brings together public reporting currently associated with Dropbox. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

1

Last 28 days

recent published signals

1

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 25, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Dropbox. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Dropbox

Dropbox logoPhishing
High

Dropbox Suffers Data Breach in Phishing Attack Targeting GitHub Account

Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.

Dropbox

FAQ

Questions about Dropbox cybersecurity reporting

What does the Dropbox page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Dropbox.

Does every mention of Dropbox appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.