
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
dropbox.com
What happened
In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk. A large volume of data totalling over 68 million records was subsequently traded online and included email addresses and salted hashes of passwords (half of them SHA1, half of them bcrypt).
Data exposed
Frequently asked questions
The Dropbox data breach occurred on July 1, 2012. It was added to Have I Been Pwned's breach catalog on August 31, 2016.
68,648,009 accounts were affected by the Dropbox data breach, according to Have I Been Pwned's records.
The Dropbox breach exposed the following data types: Email addresses, Passwords.
Yes. Have I Been Pwned has verified the Dropbox breach, meaning there's confirmed evidence the exposed data is genuine and tied to real accounts.
Use KazaSec's free Email Breach Checker (/tools/breach-check) to check whether a specific email address has surfaced in the Dropbox breach, or any other known breach — the tool never stores what you search.
Our free Email Breach Checker tells you whether a specific email address has surfaced in this breach — or any other known breach — without ever storing what you search.
Check your email →Talk to us about this
We help organizations find and fix the gaps that lead to a breach, before they do.