Incident · 8-K Item 1.05
Dropbox reports unauthorized access to the Dropbox Sign production environment
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Dropbox disclosed on May 1, 2024 that it had become aware on April 24 of unauthorized access to the production environment of Dropbox Sign, the e-signature product formerly called HelloSign. The company said the exposure reached every Dropbox Sign user's email and username.
Scope as Dropbox described it
The filing listed what the actor reached. For some users, the exposure went further.
Dropbox said it had no evidence that document contents or payment information were accessed, and it believed the incident was limited to Dropbox Sign infrastructure rather than other Dropbox products. It did not consider the incident reasonably likely to be material to its overall operations and had not determined that it would materially affect its finances.
Unanswered in the filing
The number of Dropbox Sign users is not given, nor how the actor first reached the environment. The log holds no amendment.
Sources
- 2024-05-01 · ADropbox, Inc., Form 8-K (SEC EDGAR), published May 1, 2024
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.