Skip to main content
Back to overview
High

Dropbox Suffers Data Breach in Phishing Attack Targeting GitHub Account

Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13.

Key points

  • Dropbox's GitHub account was compromised on October 13.
  • Attackers accessed 130 code repositories containing sensitive data, including API keys.
  • The breach was caused by a phishing campaign targeting Dropbox employees, impersonating CircleCI.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jul 23, 2026
Updated
Jul 25, 2026
Confidence
High
Evidence
4 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

DropboxData DisclosureDropboxGitHubAPICircleCIOne-Time PasswordOTPWhile theWebAuthn and

Quick context

Questions about this signal

What happened in this signal?

Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.

When was this signal reported?

Shadow Tier lists Jul 23, 2026 as the signal date.

Which organization is connected to this signal?

Dropbox is the organization connected to this public signal.

Explore Dropbox
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence