Dropbox status: access issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Dropbox is a file hosting service operated by American company Dropbox, Inc., headquartered in San Francisco, California, that offers cloud storage, file synchronization, personal cloud, and client software.
Problems in the last 24 hours
The graph below depicts the number of Dropbox reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Dropbox. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Dropbox users through our website.
- Errors (75%)
- Website Down (25%)
Live Outage Map
The most recent Dropbox outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Errors | 1 month ago |
|
|
Website Down | 1 month ago |
|
|
Errors | 1 month ago |
|
|
Errors | 1 month ago |
|
|
Sign in | 3 months ago |
|
|
Errors | 4 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Dropbox Issues Reports
Latest outage, problems and issue reports in social media:
-
Eyal Benishti (@eyalbd1) reported@BleepinComputer Password and 2FA were both fine here. Neither was in the path, because Dropbox trusted Lenovo's word that the attacker owned the email address. Every federated login is a bet that somebody else's email verification is not broken.
-
160 IQ haver Randy (@MinionTripper) reported@mittsh why would anyone use dropbox you can just setup an ftp server on a linux machine!
-
EFANI Secure Cellphone Service (@efani) reported🚨 Around 5,000 Dropbox accounts were accessed without authorization in August after attackers abused a weakness in the way Dropbox trusted Lenovo ID authentication. The attack did not require victims’ Dropbox passwords. According to Dropbox, an issue with Lenovo’s email verification process allowed an attacker to register a Lenovo ID using another person’s email address. Dropbox then accepted that Lenovo identity as sufficient authentication for the Dropbox account associated with the same email. Unauthorized access occurred between August 4 and August 21. Files were viewed or downloaded in fewer than a third of the affected accounts. The security problem here is bigger than one flawed login flow. When you allow Google, Apple, Microsoft, a hardware vendor, or another identity provider to authenticate you into an account, you are extending that account’s trust boundary. Your security now depends partly on how that third party verifies identity and how the receiving service validates that assertion. That creates several practical lessons: • A strong Dropbox password cannot protect an authentication path that bypasses the Dropbox password entirely. • Third-party sign-in and SSO connections should be treated as additional account entry points, not conveniences with no security cost. • Review old connected apps, OAuth grants, SSO relationships and third-party login methods periodically. Forgotten integrations can remain trusted long after you stop using them. • Enable MFA wherever possible. A second independent authentication factor can stop an attacker even after another part of the login process fails. • Sensitive cloud storage deserves extra scrutiny. Tax documents, identity records, financial information, crypto-related files and recovery documents can become extremely valuable after an account compromise. Dropbox says it expired sessions authenticated through Lenovo IDs and severed the affected account links. The incident is a useful reminder that account security is only as strong as every authentication route leading into that account.
-
Founder Tribune (@Founder_Tribune) reportedDrew Houston, founder of Dropbox, on the day the scoreboard gets switched off: For your entire life, the water has come out of one hose. Then, as he put it to MIT's graduating class: "Today, one valve shuts off and now your job is to go out and find a new hose." His hose was Dropbox. Yes, building the company was "the most exciting and interesting and fulfilling experience of my life." But he immediately flagged the half nobody hears: "What you probably don't know, and what I haven't really talked about, this has also been the most painful and humiliating and frustrating experience, too." Not hard. Humiliating. He said he could look back over the years and not even count the number of things that had gone wrong. Then: it doesn't matter. Nobody has a 4.0 in real life. Once you're done with school, Houston said, the whole idea of a GPA just goes away. Bill Gates's first company made software for traffic lights. Steve Jobs's first company made plastic whistles that let you make free phone calls. Neither was successful, and in Houston's words, "it's hard to imagine these guys were too worried about it." Here's why that lands harder than the usual fail-fast sermon: A GPA is an average, every error permanent, weighted, dragged forward forever. It rewards never being wrong. What comes after is a maximum. The misses are discarded. Only the peak is scored. Most people struggle after graduation because they keep playing an average game inside a maximum game. "From now on, failure doesn't matter. You only have to be right once."
-
Joachim Voth (@joachim_voth) reported@DropboxSupport why can I only use one core for indexing? Most machines have MANY nowadays. Download speed is not the issue, it is almost always the ultra-slow indexing that dropbox does with only one CPU core active. Am I seeing this right? Why can we not dedicate 5 or 8 cores to something that really slows down your users?
-
Craylor (@craylor) reportedHas anyone else abandoned @Dropbox after trouble with the File Provider update? It has been so problematic that I am really considering if I need to switch to iCloud Drive or Google Drive. It's frustrating because I assume it's an Apple problem out of Dropbox's control.
-
Daniel Foerster (@pydsigner) reported@colemickens @Dropbox Federated login really needs to be opt-in per provider. I shouldn't be able to log in using Lenovo (or Google, Facebook, Microsoft...) unless I used that provider during account creation or added it afterwards.
-
21Rates (@21RatesHQ) reportedBitcoin security isn't optional anymore. It's survival. The last few weeks: → Dropbox got hacked → Byte Federal (US Bitcoin ATM operator) had attackers target data on 58,000 customers, names, addresses, SSNs → A Trezor supplier leaked customer address data → The LA City Attorney's Office lost 7.7 TB of data, including police records → Coldcard found a flaw in its seed generation that could let attackers steal funds This isn't a string of bad luck. It's the new normal. KYC makes full privacy impossible in most places. But you still control part of your attack surface. Simple moves that actually help: • Use email aliases, a unique address per service • Same with phone numbers where you can • Treat every unexpected email, call, or text as hostile until proven otherwise Attackers combine data from multiple leaks to build your profile. The more your identifiers overlap across services, the easier that is. You don't need to be a victim first to start taking this seriously. What's one step you're taking this week to lock things down?
-
ericleebristol (@iamericbristol) reportedEmail scams but they also use a press cloud server that can hold up to millions of emails and send out messages in a bulk but to hundreds of people complicated when it comes to taking down email scams cuz you have to find where they coming from answer in a cloud compressed server that can hold up to millions of emails frequently combine compressed attachments (like ZIP, RAR, 7Z, or TGZ files) with cloud storage or servers to deliver malware, phishing pages, or credential-stealing links while trying to bypass security filters. Common patterns 🚩Malware in compressed attachments: Attackers send emails with ZIP or similar archives containing executables, scripts (VBS/JS), or disguised files. Some use specially crafted or nested ZIPs, password-protected archives (password given in the email body), or less-common formats that email gateways may not fully unpack or scan. Opening/extracting the archive can install remote-access tools, stealers, or ransomware. Cloud storage phishing (“storage is full” or similar alerts): Emails impersonate Google Drive, OneDrive, iCloud, Dropbox, or generic “Cloud Storage” services. They claim storage is full, a payment failed, or files will be deleted, creating urgency. Links often point to real cloud infrastructure (e.g., Google Cloud Storage Azure Blob, or other legitimate buckets) that host redirect pages or fake login/upgrade forms. This makes the links look trustworthy and helps them pass filters🚩.
-
Jameson Lopp (@lopp) reportedBusy morning in cybersecurity land: * Potentially massive Dropbox account compromise * Fake BitKey desktop software phishing email * X password reset email deluge * Protonmail outage
-
The Dollar Bin Vulture (@BinVulture) reported@HalloweenYrRnd This is fake, unhinged take on a very real problem. No one "deserves" a movie, that doesn't even make sense. But, with modern day digital distribution there is no meaningful cost to actually releasing a project. They can tweet out a DropBox link and call it a day.
-
Danny Grinberg (@DannyGrinberg) reported@DropboxSupport I DMd you guys but pandadoc is looking great right now ngl its an error when you have an existing dropbox sign trial and you try to upgrade to the api version it wont let you (insane)
-
Martin (@martin_valchev_) reportedSmall feature, real problem: Handing a WordPress site to someone else usually means FTP credentials, database dumps, or a shared Dropbox folder that stays there forever. A link that expires and can be revoked is just... better. Security shouldn't require discipline. It should be the default.
-
siamkidd (@SiamKidd) reportedNow the dust has settled with the SN24 Quasar debacle, I thought I'd share some info which would shine a slightly more positive light on the Quasar team. A few weeks ago, they approached DSV to raise $280k. They said they had big developments, some breakthroughs with a new model and that they needed capital for the training run. At the time, bear in mind that their alpha was strong, they were largely in good favour of the community and Const was still a firm backer/supporter of Quasar. And he held the keys. And they were to appear on Novelty Search soon. So it ticked a bunch of boxes. Anyway, we agreed, as we are always keen to help teams. But the issue was that I was away for 3 weeks and I never travel with crypto capability. And anytime any money moves around in DSV it's a right palava as we have 3rd party regulated custodians and have to jump through all sorts of hoops, (as social engineering with deepfakes is a very real threat). So we were able to jump through some hoops and ping over $104k to begin with and then the rest at a later date. Then we had those 2 days of madness at the beginning of the week and Quasar is no more. There's been all sorts of accusations and my view on all this is that there has just been terrible decision making, that's all. Announcements of announcements, over-exaggerating claims, giving a 24 hour deadline to offer proof, delivering it 2-3 days late and then walking back on some of the claims etc etc. I mark this down to simply their very young age and no business experience. But I don't think they are scammers. Just some very bright kids who's first experience of business is a subnet, which is like drinking water via a fire hydrant! And a pertinent piece of info behind that, is that they were very willing to return our funds. So as of today, that $104k has returned safely back to DSV. Their time as subnet owners is over and so there was a fear that we wouldn't get a penny back. But it wasn't the case. So do take this into consideration the next time you hear someone calling them scammers. With regards to Const, I think he too has also had a bit of an unfair ride with some of the comments I've seen. Const has had probably the roughest time with SN24 and is massively down from it all. He initially bought the slot from us, then reimbursed the team twice after 2 hacks, given them 6 figures in compute credits and more. So it really is fair that he keeps the slot. And I'm sure he'll find a good team for it. Also he is the founder of Bittensor. Not the CEO. He can't have detailed DD and optics on every single person and subnet in the ecosystem. And if he backs a subnet, it doesn't necessarily mean it's going to moon or be good forever. He's essentially the Federal Reserve Chairman and he has to craft policy changes to incentivise efficient growth in the ecosystem. He's the visionary and his role is to drive a path forward for Bittensor, which he is doing. And although I've highlighted personal frustrations that the chain is upgrading far too frequently...at least we are upgrading! That's one of the beauties of Bittensor. We will never be stagnant. And for the outsiders looking in, if it looks a bit chaotic, well, it is. But it's not necessarily a bad thing. You should have seen all the chaos and scandals of the companies when the NASDAQ launched! Or when ERC-20 contracts launched on Ethereum or the mountainous amount of scams on Solana with pumpfun. Hell, Bitcoin even hard forked into Bitcoin Cash due to so much in-fighting in 2017. And Ethereum suffered a $150m DAO hack in 2015/16 which forced a hard for there too. Hence why we now have ETC and ETH. So in comparison, everything is golden over here lol. In recent times, we've had/have: - SN4 partnering with Intel. - SN44 partnering with a NASDAQ PLC. - SN71 partnering with Dropbox. - SN18 getting huuuuge institutional clients. - SN107 co-authoring a research paper with OpenAI. - SN53 delivering Kimi K3 tokens cheaper than Openrouter or even Kimi. - SN95 being integrated within Hermes. - SN9 using green energy from SN110 to power their next big training run. - SN21 achieving Google Adwords campaign predictions that no company has ever achieved. - SN51 regularly doing 6 figure buyback and burns with revenue. And there's probably more that I've missed that I'm not aware of. Anywho, the future is bright! Have a good weekend all!
-
StockStorm (@StockStormX) reportedDropbox $DBX says about 5,000 accounts were compromised in an August hack tied to a Lenovo ID login flaw
-
Matt Uribe (@MattUribe) reportedI can't get my @bot to login to @dropbox . Anyone else having that issue. It's kind of a big deal for what I am trying to set up with my team. No matter what, it says too many attempts when I try using chrome on my bots screen. The plugin has no place to authenticate. Also I wish I could sign an email login to each bot. Seems we can only link one for the team using outlook. I guess that's why it beta. :)
-
Jameson Lopp (@lopp) reportedOne reason I suspect the Dropbox breach may be massive is because I didn't get a login email notification when my account was accessed. Turns out, unlike every other login notification I've received from them, it went to spam. Likely due to a large uptick in their send volume...
-
Ishita Sethi (@Ishita__Sethi) reported@LoganOpSec that dropbox bit is the part that sticks. recovery without revoking access is just half a fix.
-
kingofDEpin (@kingofdepin) reported@DropboxSupport @LIBSCRUSHER we can't login and link creation etc is not working. please fix
-
Luke Elin (@LukeElin) reported👤Shadow Adoption The pattern: Staff route around the sanctioned tool, and the organisation finds out afterwards. I watched this with unauthorised modems. Then with USB drives. Then with Dropbox. Then with entire SaaS platforms procured on a personal credit card and expensed as “software.” Now it is AI the same movie, new cast, better production values. The reason is always identical and always reasonable: the sanctioned tool is slower than the job requires. Shadow adoption is not an indiscipline problem. 👊 It is a feedback signal about the official tooling, arriving through the wrong channel. The tell: Compare the usage figures for your officially sanctioned tool against what your helpdesk volume implies people are actually doing. The gap is your shadow estate. FR FR
-
Polsia (@polsia) reportedDropbox treats an 80GB Unreal project like any other folder. Mid-previz, it chokes. Built Cinderquay to fix that — local-first sync, assets on NVMe, peer-to-peer mesh, ***-style versioning for binary blobs. Studios building worlds shouldn't pay egress to anyone. Live soon.
-
M.Ellis (@MEllisPhotograp) reported@DropboxSupport I think bulk of problem is on computer / desk top yes... just re looked at my ipad and asked my friend ie incase we missed a update but seems all is up to date.. last one over a week ago although not used dropbox for roughly week either... I will try 4g hot spot before i sleep.
-
Rituraj (@RituWithAI) reported🚨 Someone built a tool that checks if your email is registered on 120+ sites — without the sites ever knowing someone checked. No notifications sent. No login attempts logged. No alerts triggered. Silent. Invisible. Complete. It's called Holehe. 16,800 GitHub stars. And the technique behind it is what makes it different from every other email OSINT tool. Here's how most email checkers work — and why they fail. Standard approach: try to log in with the email and a fake password. If the error says "wrong password" — the account exists. If it says "account not found" — it doesn't. Problem: every login attempt gets logged. Every failed attempt triggers security alerts on accounts with 2FA. Some platforms lock accounts after repeated failed attempts. The target knows someone was checking. Holehe never attempts a login. Instead it uses the "forgot password" flow — the password reset mechanism that every platform exposes publicly. When you enter an email on a forgot password page, the platform has to check whether that email exists in its database. It tells you: "we sent a reset link" or "no account found." Holehe reads that response. Gets the answer. Never touches the login flow. Never triggers a security alert. Never logs an access attempt against the account. The platform confirms whether the email exists. The account owner never finds out anyone asked. Here's what 120+ platforms looks like in practice. Social media: Twitter, Instagram, Facebook, TikTok, Pinterest, Tumblr, Reddit. Professional: LinkedIn, GitHub, Freelancer, Fiverr. Dating: Tinder, Bumble, OkCupid, Badoo, Happn. Entertainment: Spotify, Netflix, Twitch, Steam, Epic Games, Deezer. Shopping: Amazon, eBay, Etsy, Zalando, AliExpress. Services: Airbnb, Uber, PayPal, Dropbox, Adobe. And 90+ more. Every registration checked silently. Here's the use case that makes people share this. Run your own email address. See every platform that comes back positive. Then run an email address you gave to a company that claimed they'd never share it. See if it's registered on data broker sites and marketing platforms you never signed up for. See where your email has been sold or leaked to. Here's what investigators actually use it for. Journalists verifying whether a source's claimed identity matches their digital footprint. Security researchers auditing their own exposure before a public disclosure. HR teams verifying whether candidate profiles match claimed backgrounds. And the obvious: anyone who needs to know whether a specific email address belongs to a real active person — without alerting that person. Here's the wildest part. It runs async — all 120+ platforms checked simultaneously. Results in seconds. And it exports clean JSON or CSV for integration into larger OSINT pipelines. Pair it with Blackbird (which takes the confirmed email and finds linked profiles), Sherlock (which takes usernames found in those profiles and searches 400+ platforms), and Maigret (which builds the full dossier) — and you have a complete four-tool OSINT pipeline from a single email address. One command to instal. Run it on your own email first. 16.8K GitHub stars. 1.7K forks. MIT License. 100% Open Source. GitHub link in the comments 👇
-
The Redeemed Artist (@Peace_Grenade81) reportedI know I'm just screaming into the void. And there's probably less than like one or 2% of users that actually use this function. But I'm going to do it anyway. For the longest time the X app beta was absolute garbage on Android. It had serious stability problems, I couldn't use voice to text properly, and I couldn't access my memes from Dropbox, my cloud provider. The most recent change fixed all of the other problems except for my Dropbox integration. At first, I blamed X for this but I have since come to learn that the real culprit is Google. If you go into your app section and look for cloud providers they give you all sorts of choices so long as you like the choice that is Google's. Theoretically, other providers should be in here like Box or Dropbox. But Google has been playing footsie making rules about cloud provider integration and not actually approving anyone else. Google has become Microsoft. Google will tell you what cloud provider to use and it will conveniently be their own. Google will continue to upgrade their operating system closing off any other provider options or applications they simply disagree with for any reason at all. Meanwhile what this means for me is that I can't insert any memes or videos because they are all stored on Dropbox. Yeah, yeah, yeah I could go into Dropbox and then click on a photo and then share it to X and then make a post out of it. But what I can't do is respond to a post and insert a picture or a video directly through the X app. Don't know when this gets fixed, if ever. But I think it's time for Google to be investigated for monopolistic practices. I realize that this doesn't affect many people, but if you think they aren't coming for your various conveniences, I'm pretty certain that that's going to be proven wrong. Since I can't post a meme but only a local photo, here's an unrelated picture of a quilt we bought at auction. 🙄
-
Rami.Alkhaleel (@ramialkhaleel) reportedIf your camera man added him to YOUR DROPBOX and told him to download the video from your YT. Thats your team’s fault, you can’t blame Libyano for being told he can use your footage. Harrison is a good kid, but if anything, your problem is with him.
-
chaos (@konig0000) reportedSolution of yesterday’s question: Design Google Photos: the part after the boxes “Hash it and put it in S3” fails the interview. Two phones compress the same sunset differently. Same photo. Two hashes. Two rows. You just built a worse Dropbox. The system needs three IDs, not one. client_upload_id — generated on the device before the first byte moves content_hash — hash of the exact bytes you received asset_id — the thing the user sees in the library Uploads are sessions. Library entries are assets. Blobs are renditions. If you collapse those into one key, retries, edits, and shared albums all collide. 1. Retries must be idempotent on the client, not on the filename Phone goes offline mid-flight with 612 shots, 40 already half-uploaded. Each photo gets a client_upload_id the moment it enters the queue. Chunks are uploaded against that ID. Commit is PUT /uploads/{id}/complete. Same ID + same bytes → same session. Server returns the existing asset. Late packet after commit is a no-op. Filename + timestamp is not an ID. Camera roll and AirDrop will mint two. 2. Exact dupes are content-addressed. Near-dupes are reconciled. After commit: look up sha256(bytes) if it already exists for that user (or the shared album’s owner set), attach the new upload to the existing asset_id do not create a second photo The 28 shared “Goa 2026” shots that are almost-but-not-quite the library copies will miss on sha256. That is expected. Run a cheap perceptual hash (pHash / dHash) + capture time + camera model from EXIF. If distance is tiny and captured within a few seconds, mark as near_duplicate_of and do not show two tiles. Keep both blobs if you must; hide one in the UI. Two devices, two compressions, one photo in the grid.
-
Y (@ys_tachikake) reported@DropboxSupport @LIBSCRUSHER Can't login..
-
Just Matthew (@MatthewP279348) reported@Rani_Rant_Fest @iGardon Doesn't change the fact that they aren't showing the prompt, so the result is valueless. I don't read people's google shares. Put it in dropbox if you want me to read it. Lastly, calmatters is a CA bureaucracy, of course they will lay down cover for their corrupt gov.
-
Vladislav Zharkov 👾 (@_vladislavzh) reportedI have zero industry experience. None. I don't know how to use issue trackers, I need a GUI for version control, I deliver my files through Dropbox. I don't have templates, I restart or reuse every time. I don't use industry standard tools, I don't know workflows and pipelines.
-
David Carcelli (@DavidCarcelli) reported@Dropbox dude if you guys don’t get rid of this Face ID requirement I’m done. I make music and I also use a cpap. I have no problem finding something better than this nonsense. I’m asking for help not aiming harm.