Dropbox

High

About 68.6 million email addresses sat in the mid-2012 Dropbox credential file that resurfaced in 2016. Check whether your address is in that file, then treat any reused password as the first job.

68.6M
Records exposed
2012
Year
2
Data types
Free
To check
Check if you were affected — free

Quick answer — was Dropbox breached?

Yes — this page is the mid-2012 Dropbox password-database theft, later confirmed at about 68.6 million email-and-hash pairs when the file circulated in August 2016. It is not the 2024 Dropbox Sign incident. A match means your address appeared in that credential file. Check if you were affected.

What happened in the Dropbox data breach?

This catalog row is the mid-2012 Dropbox credential theft that resurfaced in August 2016 — not later Dropbox product news and not the 2024 Dropbox Sign incident. In 2012, attackers used a reused employee password to reach internal Dropbox material. Dropbox first described customer emails and spam. In August 2016 a circulating file showed about 68.6 million email addresses paired with hashed passwords from that era. Dropbox said those credentials matched an incident it had disclosed around 2012 and forced resets for accounts that still used a pre-mid-2012 password.

The circulating file was login data, not a copy of everyone's folders. Motherboard counted about 68.7 million rows across four files; this lookup lists about 68.6 million unique emails. Roughly 32 million hashes used bcrypt. The rest used older SHA-1. Dropbox described the set as hashed and salted passwords. Weak or reused passwords remain the practical risk. Dropbox told reporters it had seen no evidence of malicious access of those accounts after the 2016 reset.

The first hop was password reuse: contemporaneous reporting said an employee had reused a password that had already leaked from another service, commonly identified as the 2012 LinkedIn theft. That is why a unique work password matters as much as a unique home password. Resetting Dropbox in 2016 did not retire the same string on email or shopping sites. Learn more about what a data breach means for you.

Why was the Dropbox breach so dangerous?

The circulating file was login data, not a copy of everyone's folders. Motherboard counted about 68.7 million rows across four files; this lookup lists about 68.6 million unique emails. Roughly 32 million hashes used bcrypt. The rest used older SHA-1. Dropbox described the set as hashed and salted passwords. Weak or reused passwords remain the practical risk. Dropbox told reporters it had seen no evidence of malicious access of those accounts after the 2016 reset.

Yes, if that pre-mid-2012 Dropbox password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique Dropbox password plus an authenticator-app second factor is what ages this incident out of your life. This page is not the 2024 Dropbox Sign e-signature incident.check whether your email was exposed in this breach.

What data was stolen in the Dropbox breach?

Email addresses Passwords

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Passwords — can be used to access your accounts directly or cracked to reveal your actual password

Timeline of the Dropbox breach

Mid-2012

Attackers use a reused Dropbox employee password to reach internal material; customers later report spam to Dropbox-registered addresses

2012

Dropbox discloses an incident it then understood mainly as email-address access via the employee account

August 2016

Dropbox says it learned of an old set of email addresses plus hashed and salted passwords it believes came from the 2012 incident, and forces resets for pre-mid-2012 passwords

August 2016

A circulating file of about 68.6–68.7 million email-and-hash pairs is independently examined; about 32 million hashes use bcrypt and the rest SHA-1

31 August 2016

Dropbox tells reporters the reset covered potentially impacted users and that it had seen no evidence of malicious access of those accounts

2016–2026

Copies remain in stuffing lists; leftover reused passwords from the file still unlock other sites. April 2024 Dropbox Sign is a separate incident

Is the Dropbox breach still dangerous in 2026?

Yes, if that pre-mid-2012 Dropbox password was ever reused and has not been changed. The file is old, widely copied, and still useful for credential stuffing. A unique Dropbox password plus an authenticator-app second factor is what ages this incident out of your life. This page is not the 2024 Dropbox Sign e-signature incident.

Email addresses from 2012 do not expire as phishing targets. Unique passwords and two-factor authentication are the work. Learn how long stolen data stays dangerous.

Is this the 2024 Dropbox Sign breach?

No. Dropbox Sign (formerly HelloSign) had a separate April 2024 production-environment incident. That event is a different product and a different catalog story. This lookup slug is the core Dropbox file-storage credential theft from mid-2012, added to public indexes in August 2016.

The 2012 file lists email addresses and passwords. Contemporaneous reporting said user files and folders were not part of what circulated. The 2016 reset closed old Dropbox logins. It did not unsay the emails, and it did not rotate passwords on other sites.

If you want the “is the company reasonable to use now?” question, including Sign, use Is Dropbox safe after the data breach?. This page stays on the 2012 credential row that industry-standard breach data sources list under the Dropbox name.

  • This row — mid-2012 Dropbox emails and hashed passwords, public in 2016. Fix reuse.
  • 2024 Dropbox Sign — a separate e-signature product incident. Not this slug.
  • A match here is the password playbook. Do not invent a file-theft story from this page.

What does an EmailLeaked Dropbox match mean?

If your address is in the 2012 credential file, EmailLeaked shows a named Dropbox match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2016 file, and we do not crawl hidden markets live.

A match is not proof someone is inside your Dropbox folder this week. It is evidence that the address — and typically a password hash from that era — appeared in a file that has been public since 2016. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For a second public index, see free data breach checkers.

What to do if your email was in the Dropbox breach

1

Confirm the match and which Dropbox file it is

Run the email check if you need the named incidents in one list. This Dropbox row is 2012 credentials: emails and passwords. It is not a stand-in for Dropbox Sign 2024.

Check this email — free
2

Treat any reused password as public

Change the password on Dropbox and on every site that shared it — starting with email. Then check whether that password appears in known leaks without sending the password itself.

3

Turn on two-factor authentication

Start with email, then Dropbox. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2012 password still fails if the second factor is not SMS sitting on a leaked phone number.

4

Follow the after-breach playbook

Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.

Open the after-breach playbook
5

Read later Dropbox incidents separately

The 2024 Dropbox Sign incident is not this catalog row. The safety guide covers that history without folding it into the 2012 file.

Open the Dropbox safety guide
6

Close Dropbox if you no longer use it

Deletion does not unsay the 2012 file. Empty sharing links first, then close the leftover cloud login so an old password stops sitting around.

How to delete your Dropbox account

Frequently asked about the Dropbox breach

What happened in the Dropbox data breach this page covers?
In mid-2012 attackers reached Dropbox using a reused employee password. In August 2016 a file of about 68.6 million email addresses and hashed passwords from that era circulated. Dropbox said it matched an incident disclosed around 2012 and reset old passwords.
Were my Dropbox files stolen?
Public reporting on this incident is about account credentials — emails and hashed passwords — not a dump of everyone's stored files. The risk from this match is login reuse and phishing, not proof that a particular folder was copied.
Is this the 2024 Dropbox Sign breach?
No. Dropbox Sign is a separate e-signature product with a separate April 2024 incident. This catalog row is the 2012 core-service credential file.
How were Dropbox passwords stored?
Dropbox described hashed and salted passwords. Contemporaneous analysis of the 2016 file found a split: about 32 million bcrypt hashes and the rest SHA-1. Bcrypt is expensive to crack in bulk. Weak or reused passwords on either half are still the playbook.
How does EmailLeaked show a Dropbox match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: 2012 credentials, typically emails and passwords, not Sign 2024. We do not claim exclusive ownership of the file.
I changed my Dropbox password in 2016 — am I done?
You are done on Dropbox if that login is unique and has two-factor authentication. You are not done if the same string still opens email or another site. Change leftover reuse.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the Dropbox breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored