Dropbox Retools Malicious Link Detection After URL Exposure
Dropbox has discontinued use of a third-party vendor for URL threat screening after discovering that URLs extracted from shared documents were being exposed to the vendor's other paying customers. The company says the data shared with the vendor consisted solely of embedded URLs—never the documents themselves—and that it has no evidence of malicious exploitation.
According to Dropbox's security team, the issue came to light on February 28, 2023 through a bug bounty report. The report indicated that URLs originating from Dropbox and DocSend were present in a database used by the vendor's subscribers and partners for malware checking. Dropbox immediately suspended submissions and launched an investigation, which traced the problem to an implementation error on Dropbox's side.
The vendor's other paid subscribers and partners could see only the URLs embedded within shared Dropbox documents or uploaded to DocSend. No file contents or other document data were submitted. Access controls on those URLs—including passwords, authentication requirements, and other restrictions—remained intact.
Dropbox states that 0.5% of registered Dropbox users and 10% of registered DocSend users were affected. As a precaution, the company worked with the vendor to remove the URLs from its database. The vendor's name has not been disclosed due to contractual terms.
Why URLs Are Checked
Document sharing platforms are frequently abused by malicious actors who embed links to phishing sites or malware downloads. Scanning shared content for risky URLs is standard industry practice, and Dropbox used this vendor as one mechanism to identify unsafe links in shared documents. The company emphasizes that such scanning is a protective measure for both its customers and the broader online community.
Changes Ahead
Dropbox says it will shift its detection strategy toward behavioral signals consistent with malicious activity and will explore new ways to restrict abuse of its APIs. The stated goal remains balancing customer protection with trust.
Users who want to determine whether URLs from their documents were submitted to the vendor can contact Dropbox at [email protected]. Dropbox advises that if a URL points to content without access controls, users should consider adding a password, disabling sharing, or otherwise restricting access. Additional questions can also be directed to the same email address.



