Dropbox discloses a material cybersecurity incident
What the filing says
On April 24, 2024, Dropbox, Inc. (" Dropbox " or " we ") became aware of unauthorized access to the Dropbox Sign (formerly HelloSign) production environment. We immediately activated our cybersecurity incident response process to investigate, contain, and remediate the incident. Upon further investigation, we discovered that the threat actor had accessed data related to all users of Dropbox Sign, such as emails and usernames, in addition to general account settings.
More from Dropbox
| Started | Incident | Impact | Duration |
|---|---|---|---|
| Sep 921:36 UTC | Some customers are unable to access certain website routes and features. | major | 59m |
| Sep 322:13 UTC | Customer support via telephone may be unavailable for some users | minor | 6h 49m |
| Aug 2523:14 UTC | Some Dropbox Protect features are not working correctly | minor | 11h 47m |
| Aug 2113:18 UTC | Dropbox is not working as expected for some users | minor | 1h 55m |
| Jul 2315:12 UTC | Dropbox is not working as expected for some users | minor | 25m |
| Jun 819:43 UTC | Shared content downloads are degraded | minor | 3d 21h |
Sources: vendors' own status pages, published postmortems and SEC 8-K Item 1.05 filings, read daily. Times as reported. Logos via logo.dev; trademarks belong to their owners.