About 68.6 million email addresses sat in the mid-2012 Dropbox credential file that resurfaced in 2016. Check whether your address is in that file, then treat any reused password as the first job.
Quick answer — was Dropbox breached?
Yes — this page is the mid-2012 Dropbox password-database theft, later confirmed at about 68.6 million email-and-hash pairs when the file circulated in August 2016. It is not the 2024 Dropbox Sign incident. A match means your address appeared in that credential file. Check if you were affected.
What happened in the Dropbox data breach?
This catalog row is the mid-2012 Dropbox credential theft that resurfaced in August 2016 — not later Dropbox product news and not the 2024 Dropbox Sign incident. In 2012, attackers used a reused employee password to reach internal Dropbox material. Dropbox first described customer emails and spam. In August 2016 a circulating file showed about 68.6 million email addresses paired with hashed passwords from that era. Dropbox said those credentials matched an incident it had disclosed around 2012 and forced resets for accounts that still used a pre-mid-2012 password.
The circulating file was login data, not a copy of everyone's folders. Motherboard counted about 68.7 million rows across four files; this lookup lists about 68.6 million unique emails. Roughly 32 million hashes used bcrypt. The rest used older SHA-1. Dropbox described the set as hashed and salted passwords. Weak or reused passwords remain the practical risk. Dropbox told reporters it had seen no evidence of malicious access of those accounts after the 2016 reset.
The first hop was password reuse: contemporaneous reporting said an employee had reused a password that had already leaked from another service, commonly identified as the 2012 LinkedIn theft. That is why a unique work password matters as much as a unique home password. Resetting Dropbox in 2016 did not retire the same string on email or shopping sites. Learn more about what a data breach means for you.
Why was the Dropbox breach so dangerous?
The circulating file was login data, not a copy of everyone's folders. Motherboard counted about 68.7 million rows across four files; this lookup lists about 68.6 million unique emails. Roughly 32 million hashes used bcrypt. The rest used older SHA-1. Dropbox described the set as hashed and salted passwords. Weak or reused passwords remain the practical risk. Dropbox told reporters it had seen no evidence of malicious access of those accounts after the 2016 reset.
Yes, if that pre-mid-2012 Dropbox password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique Dropbox password plus an authenticator-app second factor is what ages this incident out of your life. This page is not the 2024 Dropbox Sign e-signature incident.check whether your email was exposed in this breach.
What data was stolen in the Dropbox breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Passwords — can be used to access your accounts directly or cracked to reveal your actual password
Timeline of the Dropbox breach
Mid-2012
Attackers use a reused Dropbox employee password to reach internal material; customers later report spam to Dropbox-registered addresses
2012
Dropbox discloses an incident it then understood mainly as email-address access via the employee account
August 2016
Dropbox says it learned of an old set of email addresses plus hashed and salted passwords it believes came from the 2012 incident, and forces resets for pre-mid-2012 passwords
August 2016
A circulating file of about 68.6–68.7 million email-and-hash pairs is independently examined; about 32 million hashes use bcrypt and the rest SHA-1
31 August 2016
Dropbox tells reporters the reset covered potentially impacted users and that it had seen no evidence of malicious access of those accounts
2016–2026
Copies remain in stuffing lists; leftover reused passwords from the file still unlock other sites. April 2024 Dropbox Sign is a separate incident
Is the Dropbox breach still dangerous in 2026?
Yes, if that pre-mid-2012 Dropbox password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique Dropbox password plus an authenticator-app second factor is what ages this incident out of your life. This page is not the 2024 Dropbox Sign e-signature incident.
Email addresses from 2012 do not expire as phishing targets. Unique passwords and two-factor authentication are the work. Learn how long stolen data stays dangerous.
Is this the 2024 Dropbox Sign breach?
No. Dropbox Sign (formerly HelloSign) had a separate April 2024 production-environment incident. That event is a different product and a different catalog story. This lookup slug is the core Dropbox file-storage credential theft from mid-2012, added to public indexes in August 2016.
The 2012 file lists email addresses and passwords. Contemporaneous reporting said user files and folders were not part of what circulated. The 2016 reset closed old Dropbox logins. It did not unsay the emails, and it did not rotate passwords on other sites.
If you want the “is the company reasonable to use now?” question, including Sign, use Is Dropbox safe after the data breach?. This page stays on the 2012 credential row that industry-standard breach data sources list under the Dropbox name.
- This row — mid-2012 Dropbox emails and hashed passwords, public in 2016. Fix reuse.
- 2024 Dropbox Sign — a separate e-signature product incident. Not this slug.
- A match here is the password playbook. Do not invent a file-theft story from this page.
What does an EmailLeaked Dropbox match mean?
If your address is in the 2012 credential file, EmailLeaked shows a named Dropbox match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2016 file, and we do not crawl hidden markets live.
A match is not proof someone is inside your Dropbox folder this week. It is evidence that the address — and typically a password hash from that era — appeared in a file that has been public since 2016. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For a second public index, see free data breach checkers.
What to do if your email was in the Dropbox breach
Confirm the match and which Dropbox file it is
Run the email check if you need the named incidents in one list. This Dropbox row is 2012 credentials: emails and passwords. It is not a stand-in for Dropbox Sign 2024.
Check this email — freeTreat any reused password as public
Change the password on Dropbox and on every site that shared it — starting with email. Then check whether that password appears in known leaks without sending the password itself.
Turn on two-factor authentication
Start with email, then Dropbox. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2012 password still fails if the second factor is not SMS sitting on a leaked phone number.
Follow the after-breach playbook
Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.
Open the after-breach playbookRead later Dropbox incidents separately
The 2024 Dropbox Sign incident is not this catalog row. The safety guide covers that history without folding it into the 2012 file.
Open the Dropbox safety guideClose Dropbox if you no longer use it
Deletion does not unsay the 2012 file. Empty sharing links first, then close the leftover cloud login so an old password stops sitting around.
How to delete your Dropbox accountFrequently asked about the Dropbox breach
What happened in the Dropbox data breach this page covers?
Were my Dropbox files stolen?
Is this the 2024 Dropbox Sign breach?
How were Dropbox passwords stored?
How does EmailLeaked show a Dropbox match?
I changed my Dropbox password in 2016 — am I done?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the Dropbox breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored