Dropbox Outage Map
The map below depicts the most recent cities worldwide where Dropbox users have reported problems and outages. If you are having an issue with Dropbox, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Dropbox users affected:
Dropbox is a file hosting service operated by American company Dropbox, Inc., headquartered in San Francisco, California, that offers cloud storage, file synchronization, personal cloud, and client software.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Nottingham, England | 1 |
| Guayaquil, Guayas | 1 |
| Flumet, Auvergne-Rhône-Alpes | 1 |
| Irapuato, GUA | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Dropbox Issues Reports
Latest outage, problems and issue reports in social media:
-
Phillip Shoemaker (@pbsIdentity) reportedIndia just ordered hundreds of Google Firebase accounts shut down after authorities found scammers using the platform to impersonate major banks. At least 57 Firebase-hosted websites and databases were targeted for takedown this month alone. Some mimicked banks. Others distributed malicious Android apps. Some were designed to steal financial information from phones. Here's what I find interesting. Firebase isn't some shady hosting company operating out of a basement. It's Google infrastructure. That's exactly why criminals want it. We've spent years teaching people to look for obvious signs of scams. Weird domain. Broken English. Sketchy hosting. Browser warning. No HTTPS. But increasingly the attacker doesn't need to build suspicious-looking infrastructure. They borrow legitimate infrastructure. Google. Microsoft. Cloudflare. GitHub. Dropbox. Whatever gives the attack credibility and reliability. Now imagine the average person inspecting the link. They recognize Google. The connection is encrypted. The page loads perfectly. The certificate is valid. Everything their brain has been trained to interpret as: SAFE may technically be true. Except the person controlling the page is a criminal. That's an important distinction. HTTPS proves your connection to the website is encrypted. It does not prove the person operating the website is honest. A Google URL proves Google is providing infrastructure. It doesn't necessarily prove Google created the content you're looking at. The little padlock was never a morality detector. We just accidentally trained an entire generation to treat it like one. India says scammers have increasingly shifted toward Firebase because its legitimate development tools and database functionality make it useful infrastructure for fraudulent sites and apps.
-
Tony Sibert (@AiRiskBytes) reported~5,000 Dropbox accounts were breached through Lenovo IDs the victims never created. Attackers registered 'verified' identities on other people's email addresses...the federated login did the rest. Your account is as strong as the weakest identity provider your platform trusts for you. Nobody asked the users. Do you know every IdP your SaaS vendors accept on your behalf?
-
Eric Smith (@Eric_Smith08) reportedThe full math. What he replaced and what he saved: 1.Dropbox ($12/month) → Google Drive (15 GB) + OneDrive (5 GB): $144/year saved 2.Zoom ($13/month) → Google Meet (60-min calls, 100 participants): $156/year saved 3.Notion ($10/month) → Google Keep + Google Docs + OneNote: $120/year saved 4.Todoist ($5/month) → Microsoft To Do: $60/year saved 5.Slack ($8/month) → Microsoft Teams free tier: $96/year saved 6.Grammarly ($12/month) → Microsoft Editor + Gemini/Copilot for rewrites: $144/year saved 7.Adobe Acrobat ($15/month) → Google Drive PDF viewer + Edge PDF tools + Word Online conversion: $180/year saved 8.Trello ($10/month) → Microsoft Planner: $120/year saved 9.ChatGPT Plus ($20/month) → Google Gemini + Microsoft Copilot (free tiers): $240/year saved Total monthly cost before: $137 Total monthly cost after: $0 Annual savings: $1,644 Total setup time: one weekend Saturday for Google migrations, Sunday for Microsoft configurations. Accounts created: 0 (he already had both) Apps downloaded: 3 (Microsoft To Do, Teams, OneNote all free) Browser extensions installed: 1 (Microsoft Editor free) Every replacement runs on accounts he created years ago. The tools were sitting behind the same login he uses for Gmail and Outlook unused, unconfigured, and paying rent to 9 other companies that built the same features on top of what Google and Microsoft were already giving away.
-
Nathan (@arcane_bloom) reportedHe was OpenAI's first business hire in 2018. This week, after eight years, he walked out the door. > Brad Lightcap > studies economics and history at Duke, starts as a JP Morgan investment banking analyst > moves into strategic finance at Dropbox, then joins Y Combinator's Continuity Fund > meets Sam Altman through YC, gets pulled into a tiny nonprofit called OpenAI in 2018 as its first business hire > becomes CFO, then rises to COO, helps run the company through the ChatGPT launch and its climb to the most valuable startup on earth > moved off the COO title in April 2026 into a vague "special projects" role > in August, posts on X that he's leaving after eight years to "start something new" > his exit lands one month after product chief Fidji Simo also stepped down > walks away right as OpenAI preps a monster IPO on an $852 billion valuation
-
Jameson Lopp (@lopp) reportedBusy morning in cybersecurity land: * Potentially massive Dropbox account compromise * Fake BitKey desktop software phishing email * X password reset email deluge * Protonmail outage
-
Jaclyn Forero | UGC & Paid Social Strategist (@jaclynforero) reported“We need more UGC.” Do you? Or do you currently have 46 videos of attractive women standing in beige kitchens holding your product and saying: “I’m literally obsessed.” Because those are two very different problems. More creators ≠ more creative strategy. You can hire 10 creators, get 30 videos back, and still end up with a very expensive Dropbox folder full of… basically the same ad wearing different earrings. The part that actually matters happens before anyone presses record: Customer research. Different angles worth testing. Hooks that aren’t all “POV: you finally found…” Scripts that provide structure without making a normal human sound like they’re reading the terms and conditions. Casting creators for the concept instead of just asking, “Does her house look expensive?” Enough B-roll that the editor doesn’t have to perform a small miracle in Premiere Pro. And then — this part is apparently controversial — looking at the performance data and using it to decide what to make next. Recently, I led creative strategy for a top medical-grade-skincare brand's paid social campaign across research, concepts, scripting, creator direction, and post-production. Some of the winning creative generated approximately 2.3x ROAS during testing. My biggest takeaway: UGC works a lot better when you stop treating creators like content vending machines and start treating the entire thing like a creative testing system. Anyway, if your current UGC strategy is “hire more people and hope one of them accidentally makes a winner,” I have some thoughts.
-
21Rates (@21RatesHQ) reportedBitcoin security isn't optional anymore. It's survival. The last few weeks: → Dropbox got hacked → Byte Federal (US Bitcoin ATM operator) had attackers target data on 58,000 customers, names, addresses, SSNs → A Trezor supplier leaked customer address data → The LA City Attorney's Office lost 7.7 TB of data, including police records → Coldcard found a flaw in its seed generation that could let attackers steal funds This isn't a string of bad luck. It's the new normal. KYC makes full privacy impossible in most places. But you still control part of your attack surface. Simple moves that actually help: • Use email aliases, a unique address per service • Same with phone numbers where you can • Treat every unexpected email, call, or text as hostile until proven otherwise Attackers combine data from multiple leaks to build your profile. The more your identifiers overlap across services, the easier that is. You don't need to be a victim first to start taking this seriously. What's one step you're taking this week to lock things down?
-
Andree Chao (@AndreeChao) reported@DropboxSupport Can not sign in it’s broken.
-
Sridhar Katakam (@srikat) reported@YannDecoopman How about putting the vault in Dropbox? Same problem as syncing with iCloud?
-
AiMind (@AIMind_Ai) reported3 websites replace 20 hours of googling when you build a home server. The hard part of self-hosting is not the hardware. A used HP EliteDesk and a wall-mounted NAS cost almost nothing. The hard part is not knowing what you can even run, or how to avoid breaking the system on the first command. The first keeps a catalogue of self-hosted alternatives. Look up a replacement for Google Photos, Dropbox, or Notion, and you see what already exists, how many GitHub stars it has, and whether it is still alive. Plus a weekly digest of what shipped. The second lets you run any Linux distro straight in the browser. Arch, Debian, Alpine, Bazzite. Click once, and you are inside a live system, with no evening lost to a USB stick and a real install. The third handles the worst part. Install scripts for Proxmox: Immich, Jellyfin, Vaultwarden, AdGuard, Nginx Proxy Manager. Paste one line into the console and the container comes up on its own. Immich shows 17,735 installs; Docker 36,408. Each of those services used to cost an evening of documentation and three Stack Overflow tabs. Now it is one command. The hardware takes an hour to buy. These 3 bookmarks save you a month. Names in the replies.
-
Harpreet Singh (@hrprtsingh9) reported@jgreze @Dropbox Half of every revenue problem is a company being too polite to ask. The intern just asked.
-
Saurabh | Celsius 233 (@Celsius233Books) reported@colemickens @Dropbox lenovo and security issues...takes one back to the 2015 Superfish scandal where lenovo was visually scanning every single webpage you visited to sell ads
-
Daniel Foerster (@pydsigner) reported@colemickens @Dropbox Federated login really needs to be opt-in per provider. I shouldn't be able to log in using Lenovo (or Google, Facebook, Microsoft...) unless I used that provider during account creation or added it afterwards.
-
Tim Geisendoerfer (@djgeisi) reported@JXXSL @DropboxSupport Yep we saw the same errors now we get 501 errors on the upload endpoints.
-
Bit Paine ⚡️ (@BitPaine) reportedI’m not seeing this reported anywhere on my feet, but there was a terrible data breach at @Dropbox. Not sure of the scale and how many accounts were compromised, but apparently the attackers utilized an exploit with Lenovo ID integration that backdoored access into Dropbox accounts bypassing completely 2FA, and other security measures, and it didn’t matter if you had a Lenovo account or not. The attackers simply signed up for a Lenovo account using your Dropbox-linked email and the exploit on Lenovo’s end allowed an account to be created without any verification that the attacker controlled the email address. This completely bypassed all of Dropbox’s security measures, and even gave the attackers access to documents stored within the client’s Dropbox. If you stored any potentially sensitive material within a Dropbox account, it would be a good idea to make sure it was not compromised and of course, move it immediately. Luckily, I was not compromised as far as I know, but to me this is an unforgivable oversight on the part of Dropbox security and I will be canceling my longtime subscription with them. Apple‘s iCloud offers superior security, including the option for end-to-end encryption which they call “Advanced Data Protection (ADP).” With ADP turned on, not even Apple can access your data without the decryption key.