Hi Dropboxers, Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm. A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions. We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we’ll immediately notify the account owner. If you’re concerned about any activity that has occurred in your account, you can contact us at
https://www.dropbox.com/support. This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again. -Arash
[Update - Mon, 10:46pm] - We're working around the clock to gather additional data and continue to review logs for potentially unauthorized activity. We aim to notify users who had login activity during the period within the next few hours. We are sorry for this and regardless of how many people were ultimately affected, any exposure at all is unacceptable to us. We will continue to provide regular updates.
[Update - Tue, 2:49am] - At this point, the accounts that logged in during the period have been emailed with additional activity-related details for review. If you have any questions or concerns, please contact us at
https://www.dropbox.com/support.
[Update - Fri, 1:59pm] - Today we sent an email directly to users whose accounts were likely compromised during the recent security lapse. According to our records, there were fewer than a hundred affected users and neither account settings nor files were modified in any of these accounts. Our team has been working tirelessly to review what happened and to make sure that it never happens again. At this point, we have contacted all these users and provided them more detail. We will continue to provide updates when available.
Related Articles

Beyond the office-versus-remote debate: Why we lack focus at work and what to do about it
By Dropbox Team

Introducing a seamless camera-to-cloud experience with Dropbox, Dropbox Replay and Atomos
By Dropbox Team

All your feedback, all in one place: Dropbox Replay’s new feature with Avid Media Composer
By Dropbox Team

Dropbox VP of Design speaks about the future of culture and communication at FORTUNE Reimagine Work Summit
By Dropbox Team

Dropbox Foundation’s new partners fight for racial and environmental justice, youth and LGBTQ+ rights
By Dropbox Team

Dropbox, HelloSign, Asana, Salesforce, and Slack work together to support organizations impacted by COVID-19
By Dropbox Team

Dropbox joins Bay Area companies to distribute $22M in funding in response to the COVID-19 crisis
By Dropbox Team

Drew talks evolution of Dropbox at Europe’s biggest founders festival Bits & Pretzels
By Dropbox Team
Dropbox is an April 2019 Gartner Peer Insights Customers’ Choice for Content Collaboration Platforms
By Dropbox Team

Dropbox is acquiring HelloSign to improve document workflows for hundreds of millions of users
By Dropbox Team
Dropbox Announces Full Exercise of Underwriters’ Option to Purchase Additional Shares
By Dropbox Team

Dropbox unveils colorful new look and global brand campaign focusing on creative energy
By Dropbox Team
Dropbox launches 2017 Hurricane Relief Fund to respond to Harvey and Irma recovery efforts
By Dropbox Team
Introducing Enterprise Mobility Management (EMM) to keep you safe and productive on the go
By Rob Baesman

Dropbox for Business achieves ISO 27018 certification, an emerging international cloud standard for privacy and data protection
By Tolga Erbay