cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
What’s new: end-to-end encryption, Replay and Dash updates. Find out more about these updates, new features and more here.

Security and Permissions

Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Join team/merge account potential compromise

Join team/merge account potential compromise

jimwc
Helpful | Level 5

I have lodged a ticket with support on this but I am concerned about a potential security issue. And want to see if I can get some additional information more quickly or find alternative communication, such as a support line to talk to someone in real time. 

 

I received an email to join a drop box team. As I have been trying to provide support to a potential client I didn't think much of it. I saw the merge accounts button and thought, ok I don't really want to do that but let's see if there's more information. NO! It just starts merging the account.

 

I am not worried about my account. It was only created for troubleshooting the client's problem. There is nothing in it except a bunch of "test files" but it looks like a colleague has also merged their account too. We don't know if this is malicious but I would like to see if there is a way to extricate my colleague's account from this situation without contacting this potential client (who we know nothing about). 

 

Is there a way we can permanently delete our files or account? This seems like a massive security issue as the admin of the team can access everything in a drop box with nothing less than a carelessly clicked URL. 

15 Replies 15

Heather C.19
Helpful | Level 5

I just had this happen to me today! A friendly community manager here let me know that the only way you'll be able to get your accounts back is to contact their admin and have them start you a personal account. My client now has all my other client files including things like my tax returns for 2015-2023. Did I know I would be being merged into their account? Nope! I thought I was getting access to a folder. So far Dropbox has been extremely unhelpful and this is a HUGE SECURITY ISSUE they have been ignoring for what looks like about 5 years (Twitter users from 2019 complained about this) Good luck!

jimwc
Helpful | Level 5

Heather, thanks for the heads up. I am shocked and I commiserate with you. It definitely should not be so easy to lose control over your own files. I believe my colleague thought they were also gaining access to shared files. I definitely know there was no interest in merging accounts. How do dropbox let this go on? It's an exfiltrator's goldmine. I will definitely be suggesting more secure services after this.

Heather C.19
Helpful | Level 5

You're welcome Jim! I'm sorry it happened to you and your friend too! It feels like we've been hacked. I'm also shocked. It seems really easy for anyone to send a link to join a team folder and shoop–suddenly have a ton of free data! I'm moving my files to something more secure. In doing some investigating I also found out that DB employees can look at your files whenever?? That's terrifying and a huge security risk for me and everyone using DB for anything personal.

jimwc
Helpful | Level 5

It is absolutely terrifying. I hope your client does the right thing. Seems like the sort of thing that should have multiple steps and prompts to conclude the process.

 

Did you manage to find a call line number, or did you have to wait for a response to a submitted ticket?

 

One of my concerns is if an admin can access files/folders owned by a user outside of the team.

Heather C.19
Helpful | Level 5

They can! Admins are able to access all files in the team folder, including your previously "personal" ones. They can delete, share or remove your access to those files. https://help.dropbox.com/account-access/admin-control

Heather C.19
Helpful | Level 5

I think I've found a workaround, you have to create a new personal account using a new email. Then you can link the two dropboxes and copy your files into your personal account on your desktop. Then download everything from desktop to your hard drive and unlink the business. Then I think you should be able to delete the files from their dropbox. The only thing is making certain you have every file fully downloaded and the uncertanty if the admin is able to reactivate your deleted files from the dropbox trash unless you can convince them to delete your account.

I haven't heard back from support, I imagine it will be several days?

jimwc
Helpful | Level 5

Headaches! We have our files downloaded. I was able to download everything directly from the "team" account.

Can you use the linked account to control your merged account ie. delete it? I think unlinking from the business only removes your personal account from it - is that right? The Admin can undelete items - unfortunately. Otherwise, they sit there for 30 days before being deleted permanently. I think 30 - I read it somewhere recently but am not 100%. 

 

Heather C.19
Helpful | Level 5

Oh I'm glad to hear that! Just make sure you've got those files in a place separate from the dropbox folder or when the admin deletes your account they'll disappear. Unfortunately only an admin can delete your account from their team folder, ugh.

jimwc
Helpful | Level 5

It is also the admin that can only permanently delete files. I mean, makes sense. If your account wasn't hijacked. 

Need more support?
Who's talking

Top contributors to this post

  • User avatar
    Heather C.19 Helpful | Level 5
  • User avatar
    jimwc Helpful | Level 5
What do Dropbox user levels mean?