Need to see if your shared folder is taking up space on your dropbox 👨💻? Find out how to check here.
Forum Discussion
radenkovic
3 years agoHelpful | Level 5
Received 3 2FA emails in one minute, but 2FA was not enabled on my account
Hi all,
A strange thing happened today, I've received 3 emails in sequence with content:
Hi [MY FIRST NAME],
Finish signing in to Dropbox with this one-time security code:
[ 6 DIGIT CODE]
If you didn't try to sign in, don't worry. You can safely ignore this email.
I freaked out because you can receive 2FA only if you enter the correct password. Upon investigating I figured out that my account does NOT have 2FA enabled!!!
Adding headers here (redacted):
From: Dropbox <no-reply@dropbox.com> To: [MY EMAIL] CC: Subject: [6DIGITS CODE] is your Dropbox security code Date: Mon, 26 Dec 2022 11:03:37 +0000 Message-ID: <010001854e1a3116-24a80716-e9c4-40f4-94d3-1ebadcdc1fa9-000000@email.amazonses.com> X-Dropbox-Message-ID: 16683002164785652191 Feedback-ID: 1.us-east-1.syWQ1+fF8Wo1tY8y/+s85ptiAKu7bILK6PHyxwpB+xo=:AmazonSES X-SES-Outgoing: 2022.12.26-54.240.39.228
Headers look legit, it seems that email is not spoofed.
Is this some sort of bug, can someone from dev/support can explain what happened? There was this Lastpass breach a few days ago and I am not sure if those are connected.
TLDR; Received 2FA emails, however 2FA is not enabled on my account.
Just in case I updated my password once again (was changed a week ago).
44 Replies
Replies have been turned off for this discussion
- radenkovic3 years agoHelpful | Level 5
Megan feel free to reach me via email (it's the same I'm using to login to this account).
- Megan3 years ago
Dropbox Community Moderator
- arana3 years agoHelpful | Level 6Hi Megan, You can email me as well.
- Hannah3 years ago
Dropbox Community Moderator
Hey arana, you've got mail as well!
- willywonka3 years agoHelpful | Level 5
Hi,
can you reach out to me via email as well? as the exact same thing happened to me. Thank you
- Hannah3 years ago
Dropbox Community Moderator
Not a problem, willywonka!
I just sent you an email as well, so make sure to get back to me, when you have a chance.
- Randy903 years agoHelpful | Level 5Just chiming in to say I have also been hit with the 3 emails in the span of less than a minute.
This is happening too many times now to be a coincidence, fortunately I don’t have any sensitive files on my account but that’s not the point, a LOT of people are getting these 3 OTP emails in quick succession for it to just be brushed off, as someone said in this thread earlier there has to be either a bug/glitch or a security flaw with Dropbox itself. - MichaelEngstler3 years agoNew member | Level 2
Hello,
I've received two emails on 19/12/2022 requesting to finish singing up by providing the one-time password.
- I haven't logged in or used my Dropbox account for more than an year
- My password is very complicated and was generated by LastPass and is not shared between any accounts
- I've already conducted all counter-measures such as changing password (I already have 2FA turned on).
- Lastly, I didn't use Dropbox on 19/12/2022 in anyway
My one and single concern is - Did someone manage to enter correct credentials to my account, or was a glitch/bug from DropBox?
This is very important for me as it's close to the dates LastPass was breach and I need to understand if the email from DropBox was a legitimate login attempt with my password or a bug from DropBox.
Please don't simply suggest to change password/2FA as I have already done that.
My only question is if someone managed to actually enter my correct password to DropBox on 19/12/2022.
We can further elaborate over email if required.
Thank you,
Michael
- radenkovic3 years agoHelpful | Level 5
I think you should open support tickets, as for now Dropbox support is clearly ignoring the issue, I am getting only generic responses to change my password and other usual stuff. However, there are a lot of indications that the problem actually exists on Dropbox side.
- MichaelEngstler3 years agoNew member | Level 2
Hey @Megan, can you please reach out to me via email as well?
The same email as my dropbox account.
Thanks
About Security and Permissions
Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.
The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.
If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X, Facebook or Instagram.
For more info on available support options for your Dropbox plan, see this article.
If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!