Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Dropbox said in 2016 that a real list of email addresses and hashed, salted passwords was tied to a 2012 security incident. Have I Been Pwned lists 68.6 million affected addresses; Dropbox later described approximately 68 million accounts. The company said it had no indication that accounts were improperly accessed as a result of the surfaced list, and reported that it notified users it believed were affected and reset passwords that had not changed since mid-2012.

What happened in the Dropbox credential leak?

The incident has two important dates: the account-access activity Dropbox disclosed in 2012, and the much larger credential list that became public in 2016.

The 2012 account-access incident

On July 31, 2012, Dropbox said credentials stolen from other websites had been used to sign in to a small number of Dropbox accounts. The company also said a stolen password was used to access an employee Dropbox account containing a project document with user email addresses. Dropbox described additional security measures, including plans for two-factor authentication and suspicious-activity detection. Dropbox’s 2012 security update

The 2016 credential list

In August 2016, Dropbox confirmed that a reported list of email addresses and hashed, salted passwords was real. The company said its analysis indicated the credentials were likely obtained in 2012 in connection with the incident it had disclosed. Have I Been Pwned records 68.6 million affected addresses, while Dropbox’s later investor filing describes approximately 68 million accounts. These are source-specific figures with different wording and rounding, not proof of two separate leaks. Dropbox’s 2016 explanation Have I Been Pwned’s breach record Dropbox’s investor filing

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

What information was exposed?

The descriptions from Dropbox and Have I Been Pwned identify email addresses and password hashes, not plaintext passwords. Dropbox described the passwords as hashed and salted. Have I Been Pwned characterizes the hashes as half SHA-1 and half bcrypt; that technical breakdown is HIBP’s reporting.

A hash is not the same thing as a readable password, but hashing and salting do not guarantee a password cannot be recovered. Dropbox’s filing notes that these techniques can make recovery more difficult without necessarily preventing it. The reviewed sources do not establish how many passwords were cracked or how many accounts were accessed using the surfaced list.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What did Dropbox do in response?

Dropbox said it emailed users it believed were affected and reset passwords for accounts whose passwords had not been changed since mid-2012. The company advised people who reused their Dropbox password on other services to change it there, too. In its 2016 statement, Dropbox said it had no indication that Dropbox accounts had been improperly accessed as a result of the surfaced list. That is the company’s account of its findings, not an independently verified conclusion about every account or the complete dataset.

Dropbox also said users who were not prompted to reset a password did not need to do anything for that particular reset campaign. That statement concerns the 2016 response; anyone with a current account concern should follow Dropbox’s present security guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

What should you do if you reused your Dropbox password?

  1. Change the password anywhere it was reused. Start with email, financial, shopping, and other accounts that share the old Dropbox password. Use each service’s official website or app rather than links in unexpected messages.
  2. Give every account a different password. A unique, strong password limits the damage if credentials from one service are exposed. A password manager can help create and store distinct passwords; Dropbox’s 2012 security post also named 1Password as an example.
  3. Turn on two-step verification. Add this extra sign-in check to Dropbox and other important accounts wherever it is available. Dropbox recommended two-step verification in 2016 and currently advises enabling two-factor authentication for suspected account compromise. Dropbox account security guidance
  4. Be alert for phishing and spam. Email addresses were part of the exposed data, and Dropbox warned users to watch for suspicious messages. Do not provide a password through an email link or an unexpected sign-in prompt.

How do you check and secure a Dropbox account now?

If you suspect someone has access to your account, Dropbox’s current guidance recommends changing to a unique password and enabling two-factor authentication. Review account activity and shared content for signs you do not recognize. Dropbox’s troubleshooting guidance includes checking unfamiliar files, file version history, and sharing, and contacting support if the concern remains. Dropbox account security guidance

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the public record does not establish

  • The exact attacker or a complete chain showing how the credential list was obtained and circulated.
  • A verified number of passwords successfully cracked.
  • A confirmed count of accounts accessed using the surfaced list.

The available accounts distinguish Dropbox’s 2012 disclosure from the larger list acknowledged in 2016; they do not establish that all listed credentials were used to access Dropbox accounts.

Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.