At a glance:
- Dropbox encrypts files with AES-256 at rest and TLS in transit but holds the encryption keys itself
- No end-to-end encryption on personal plans. Optional encrypted team folders exist on Business Plus, Advanced, and Enterprise, and they are off by default
- Uses subprocessors including Google (support), Amazon Web Services (infrastructure), and OpenAI (certain AI features). Connecting ChatGPT or turning on in-product AI is a separate content path
- Six publicly reported security incidents since 2011, including bugs, a credential dump, a Sign-product breach, and a 2026 Lenovo login failure. None required breaking AES-256
- US-headquartered company. Valid legal process can reach data Dropbox can decrypt
- Not recommended for confidential files in law, healthcare, finance, or journalism unless those files live only in an encrypted team folder
- Switching to Google Drive doesn’t fix the problem due to the same default encryption model
Dropbox has more than 700 million registered users because it is simple, syncs well, and already lives on every device you own. But is it safe to put something confidential in there?
On most plans the answer is mixed. Dropbox encrypts files in transit and on disk, which is enough to stop a casual outsider, but it also keeps the keys, so the company can open what you stored. A 2026 incident made that concrete: attackers never broke the cryptography, they walked in through a login partnership, and on accounts without 2FA they could read whatever Dropbox itself could read.
Holiday photos and draft decks can live there without much drama. A customer contract or source file is a different bet, because Dropbox holds the keys unless you pay for a limited encrypted team folder and turn it on. What follows is how the encryption works, what Dropbox does with file content, the breach history, how it compares with Google Drive and email, and when you should share confidential files another way.
What “is Dropbox secure” actually means
That question sounds simple, but it actually bundles three different worries together.
1. Can a random hacker get in?
This is where Dropbox is strongest. Your files are encrypted with AES-256 on disk. Transfers are protected with TLS. You can turn on 2FA. Against an outsider trying to break in, those defences are solid.
2. Can Dropbox itself read your files?
Yes. On personal plans and standard team folders, Dropbox holds the encryption keys, so it can decrypt anything you store. Its privacy policy and sub-processor list include Google for customer support, Amazon Web Services for infrastructure, and OpenAI for certain AI features such as summarisation and search. That is not the same as every file being sent to those companies. A subpoena doesn’t need to crack your encryption if the company can just hand over the plaintext.
3. Can only the person you chose open a shared file?
Not exactly. Paid plans let you put a password on a shared link, but the file still sits on Dropbox’s servers, decryptable by Dropbox. A shared-link password is access control, not end-to-end encryption; Dropbox’s standard service is not zero-knowledge.
Dropbox, however, does offer optional end-to-end encryption for certain eligible team folders on Business Plus, Advanced, and Enterprise. When enabled, the content is decrypted only on approved devices, not on Dropbox’s servers.
In short: Dropbox protects you from a stolen laptop. In most cases, it doesn’t protect you from the vendor, a court order, or a partner that processes your file content.
How does Dropbox encryption work?
Dropbox encrypts files with AES-256 at rest and moves them over TLS. That sentence appears on every marketing page and it is true, but it is also incomplete.
The file travels through a TLS tunnel, then Dropbox encrypts it again with AES-256 on disk. On personal plans and standard team folders the company keeps those keys so it can decrypt the file for a preview, search, a legal request, or a feature you switched on.
Think of a safety deposit box where the bank keeps a spare key: the vault is locked, yet you are not the only one who can open it. End-to-end encryption works the other way round, because you hold the key and the service only stores ciphertext it cannot read. Dropbox does encrypt, but it does not, by default, encrypt in a way that shuts Dropbox out.
Dropbox encrypted folders: what they are (and aren’t)
The feature is paid, partial, and gated, so most people asking whether Dropbox is secure are on a plan where it never applies. A password on a shared link is different: the file in your account stays readable to Dropbox, and the password only gates the public URL.
- Available on Business Plus, Advanced, and Enterprise, not Basic, Plus, or a typical personal plan
- Opt-in for designated team folders, not the whole account
- Sharing outside that circle is restricted, and some collaboration features fall away
- A recovery key exists, and if you lose the keys the wrong way the data is gone for everyone, Dropbox included
Does Dropbox scan your files?
Because Dropbox holds the keys on most plans, it can look at what you stored. That is the privacy point. “Scanning” is narrower: Dropbox indexes names, types, and sizes so sync and version history work, builds previews, and on higher plans runs OCR so you can search inside scans. Public links can be hash-checked against known copyrighted material, and the business whitepaper describes malware scanning once a file is shared outside the original account.
AI is a separate tap. Connect ChatGPT or switch on in-product AI and file content can reach a processor. Dropbox’s help pages say ChatGPT only reads Dropbox after you connect the account and ask. Conversations in consumer ChatGPT may be used for model training under OpenAI’s rules; ChatGPT Team and Enterprise are different. OpenAI also appears on Dropbox’s sub-processor list for built-in LLM features, which is not the same as the ChatGPT plugin. Treat every AI switch as a decision to let another company see the file. Whether a staff member is reading the file today is the wrong test. The test is who holds the key.
What security features does Dropbox offer?
Dropbox is not empty-handed against outsiders. 2FA is available on every account, and the 2026 Lenovo incident mostly hit people who had left it off. Paid and team plans can password-protect and expire a shared link, revoke it later, and on some tiers disable downloads. Business plans add remote wipe, SSO, device approvals, and admin controls, while version history runs for 30 days on Basic and Plus, 180 days on Professional and Standard, and one year on Advanced and Enterprise. HIPAA-eligible plans and BAAs help with paperwork. They do not invent default zero-knowledge encryption.
How to password-protect a Dropbox shared link
A shared-link password protects the link against unauthorised recipients who obtain the URL, for example, through accidental forwarding, copying, or a data leak. Anyone who has the link still needs the password to open it. It does not protect the file against Dropbox, which can still decrypt the file under its standard storage model. It also does not protect against someone who is already authorised to access the file through their Dropbox account.
This feature is available on Professional, Essentials, Standard, Advanced, Business Plus, and Enterprise, but not Basic or Plus. Check Dropbox’s current plan documentation because feature availability can change.
- Open dropbox.com and find the file or folder
- Click Share, then create or open the shared link
- Open link settings
- Set a password
- Set an expiration date if the plan allows it
- Optionally disable downloads
- Send the password through a different channel than the link (a call, Signal, or encrypted email, not the same Gmail thread)
Anyone with access inside Dropbox still sees the file, and Dropbox can still decrypt it. There is no native folder password on personal plans that hides contents from the company.
Has Dropbox been hacked before?
Yes, and almost none of the incidents required someone to crack AES-256.
In 2011 a software update let anyone open an account with only an email address. In 2012 a breach exposed 68 million email addresses and passwords, a leak not fully disclosed until 2016. In 2017, deleted files reappeared in some accounts because of a restore bug, not because someone broke in. In 2022 attackers reached 130 Dropbox GitHub repositories after phishing an employee.
The 2024 Dropbox Sign incident (the old HelloSign product) is easy to mix up with core storage. An attacker reached Sign’s production environment and took names and emails, plus, for some users, phone numbers, hashed passwords, API keys, OAuth tokens, and MFA data. Dropbox said it found no evidence that document contents or payment data were taken, and Sign’s infrastructure is separate from the main file store.
Then came August 2026. Attackers abused a Lenovo ID email-verification flaw, registered a Lenovo ID with a victim’s address, and used Dropbox’s Lenovo login partnership to open the matching Dropbox account without the Dropbox password. About 5,000 accounts were touched between 4 August and 21 August. Fewer than one-third had files viewed or downloaded, and those accounts generally had no Dropbox 2FA. Dropbox expired the sessions and cut the Lenovo link. A trusted login path failed, and on a standard plan the files were already readable to Dropbox, so they were readable to whoever inherited the session.
Is Dropbox secure for confidential files?
For everyday storage (photos, lecture notes, a deck that is going to a public meeting anyway) Dropbox does a decent job, because AES-256 and TLS shut out most opportunists and 2FA makes a stolen password less useful.
Confidential files are a different bet. Personal plans have no end-to-end encryption, optional encrypted folders live on Business Plus, Advanced, and Enterprise and only on the folders you designate, and the company is American, so lawful-access rules follow the entity rather than only the data centre. Shared links get forwarded, and preview, search, and AI features process content when they are on.
IBM’s Cost of a Data Breach Report 2025 put the global average incident at USD 4.44 million and public-cloud-only cases at USD 4.68 million. Those are industry averages, not Dropbox-specific costs. “Nobody broke the crypto” is not the same statement as “nobody opened the files”.
The 2025 Thales Cloud Security Study found that only 8% of organisations encrypt 80% or more of their cloud data, even though 54% of cloud-stored data is now classified as sensitive, up from 47% the year before. That describes enterprises in general, not Dropbox customers.
Team plans add logs and optional encrypted folders, which still fail unless every confidential folder uses that extra mode. If a leak could get you sued, fined, or someone else hurt, the default Dropbox model is the wrong tool.
Who should not store confidential files on Dropbox?
Anyone whose work carries a legal or regulatory duty to keep files private.
Lawyers and law firms are the clearest example. Privilege assumes your custodian can’t casually read the file, but Dropbox holds the keys, so it can. The ABA’s 2023 TechReport is routinely cited for the finding that nearly 30% of firms had ever reported a breach. That is “ever,” not “this year.” “We haven’t been hit yet” is not a security policy.
Healthcare teams face a similar issue. GDPR and HIPAA both demand strict data controls. A Business Associate Agreement helps the paperwork, but it doesn’t create zero-knowledge encryption on Dropbox’s servers. Your patients’ records are still decryptable by the vendor.
The same logic applies to:
- Accountants holding tax files and audit documents
- Journalists protecting confidential sources
- HR departments storing identity documents and salary data
- Any small business that has accepted a customer’s confidential files
The rule is simple: if a breach of those files could trigger a lawsuit, a fine, or harm to someone, you need end-to-end encryption. On Dropbox that means a Business Plus, Advanced, or Enterprise plan, switching encryption on per folder, and accepting that only those team folders are covered.
Is Dropbox more secure than Google Drive?
Not in any way that fixes privacy.
Both encrypt with AES-256 on disk and TLS during transmission. Neither is end-to-end encrypted by default. Both are US companies that can read standard-plan files. Google’s historic business is advertising, so it has a sharper incentive to analyse content. Dropbox is not an ads company, but it still shares data under defined conditions and can pass file content to AI vendors when those features are on.
| Feature | Dropbox | Google Drive |
| Encryption at rest | AES-256 | AES-256 |
| Encryption in transit | TLS/SSL | TLS/SSL |
| End-to-end encryption | No by default. Optional encrypted team folders on Business Plus, Advanced (from $24 per user per month), and Enterprise | No by default. Limited client-side encryption in some enterprise setups |
| Zero-knowledge by default | No. Encrypted team folders are folder-level, not an account-wide zero-knowledge mode | No |
| Headquarters | US | US |
| Can access files on standard plans | Yes | Yes |
| Password-protected share links | Paid plans | Limited / different model |
| Shares data with third parties | Yes, under defined conditions | Yes, under defined conditions |
Moving the same files from Dropbox to Google Drive trades one US key-holder for another.
Is Dropbox more secure than email?
It depends on which email you mean.
Ordinary Gmail and Outlook protect messages while they travel between servers and devices, but they are not end-to-end encrypted by default. The provider can generally access content stored in the mailbox. Uploading a contract to ordinary Dropbox and emailing its link through Gmail or Outlook creates two separate exposure points: a provider-readable inbox and a provider-readable cloud file.
Dropbox can still be more practical than a raw email attachment when the file is large, when several people need ongoing access, or when you want to manage access through permissions, expiration dates, and link revocation. Password protection adds another access-control layer, but it is not the same as end-to-end encryption.
End-to-end encrypted email is preferable when the content should remain inaccessible to the service carrying or storing it. Mailfence supports OpenPGP encryption, including encrypted attachments, when the recipient’s public key is available.
If the recipient does not use OpenPGP, Mailfence also supports password-encrypted email for any email address. You choose a password, share it separately, and can set an expiration date.
| Dropbox (default) | Gmail / Outlook | Encrypted email (Mailfence) | |
|---|---|---|---|
| Default E2E | No by default. Optional encrypted team folders on Business Plus, Advanced (from $24 per user per month), and Enterprise | No | OpenPGP when keys exist |
| Vendor can read the file | Yes | Yes | No for OpenPGP content. Password-encrypted mail is locked with a password you set |
| Share with someone who has no account | Link (password extra, paid) | Yes | Yes. Password-encrypted email works with any inbox |
| Best for | Ongoing sync and collaboration | Everyday mail | Confidential send and conversation |
| Jurisdiction | US | US | Belgium / EU |
The weak point in a “secure Dropbox share” is often the unencrypted email used to send the link or password. For collaboration, Dropbox may be the better tool; for provider-blind confidentiality, properly encrypted Mailfence email is the stronger choice.
How to make Dropbox as safe as it can be
If you are staying on Dropbox, tighten the account before you tighten the marketing copy.
- Turn on 2FA with an authenticator app or a security key, not SMS if you can avoid it. Review logged-in devices and unlink Lenovo or any SSO you no longer use
- Use a password that does not appear in the 2012 dump or anywhere else
- On a paid plan, password-protect and expire every external link, then revoke the old ones
- Keep secrets out of folders that sync to every laptop and phone
- On Advanced, Business Plus, or Enterprise, put anything actually confidential only in an encrypted team folder
- Treat AI features as a content-processing switch and leave them off unless you accept another processor seeing the file
- For a one-off confidential send, skip Dropbox and encrypt the transfer
Encrypting a zip on your device before upload will hide the contents from Dropbox, but it also kills preview, search, and most collaboration, which is fine for an archive and miserable as a daily drive.
What are the best Dropbox alternatives for privacy?
If you need Dropbox-shaped sync and you want the vendor unable to read the disk, look at Proton Drive, Tresorit, MEGA, Sync.com, or pCloud’s paid Crypto folder. If the job is due diligence, use a virtual data room. Most people are not shopping for another two terabytes. They need to get one file to one person, which is a sharing problem rather than a storage-migration project.
Mailfence Documents is integrated into the same account as your email, allowing you to upload, organise, and share files before sending a link or attachment. Mailfence also supports OpenPGP encryption, which is designed to prevent us from reading properly encrypted messages and attachments, as well as password-encrypted email for recipients who do not use PGP.
Mailfence — Your secure Productivity Suite
Reclaim your Privacy with
- Messages
- Calendars
- Documents
- Groups
FAQ about Dropbox security
Can I password-protect a Dropbox file or folder?
You can password-protect a shared link on Professional and team plans, which does not hide the file from Dropbox.
What are the best Dropbox alternatives if I need zero-knowledge storage?
Proton Drive, Tresorit, MEGA, Sync.com, or pCloud Crypto if you still want sync. For a one-off confidential send, encrypted email plus Mailfence Documents is usually less work.