Small Business Teams Targeted in the 4,600 Dropbox Login Leak
HEROIC analysts found a combolist named Dropbox_Business_Logins 2 uploaded to Telegram on 19-Mar-2026, containing 4,600 records of email addresses, plaintext passwords, and URLs tied to Dropbox Business accounts. Why This Is Dangerous: Dropbox Business accounts often hold company files, client documents, and shared folders used by entire teams, so a single compromised login can expose far more than one person's data. Because these passwords are in plaintext, attackers can log in immediately without cracking anything. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each Dropbox Business login Why This Matters: Small business owners and their employees are the clear target of a leak like this, since Dropbox Business is built for teams rather than individuals. If an attacker logs into one of these accounts, they can potentially access shared client files, financial documents, or internal records, leading to business fraud, data theft, or further phishing attacks against coworkers and clients. How a Combolist Like This Works: Criminals build combolists like this one by focusing on a specific service, in this case Dropbox Business, and collecting credentials from phishing campaigns, malware, or older leaks tied to that platform. Targeting a specific business tool makes the list more valuable to buyers looking to breach companies rather than individuals. Check If You Are Affected: If your business uses Dropbox, check your account email against HEROIC's free breach scanner, which searches more than 400 billion leaked records, to see if your login was part of this exposure.
Breach Breakdown
4,600 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds