You might see that the Dropbox Community team have been busy working on some major updates to the Community itself! So, here is some info on what’s changed, what’s staying the same and what you can expect from the Dropbox Community overall.

Forum Discussion

joaochora's avatar
joaochora
Explorer | Level 4
7 years ago

Two factor problem = account lost. user since 2009.

Good afternoon Dropbox Users and Community,


Today I want to share with everyone my experience with Dropbox for, maybe, Dropbox one day think on it and find a smart solution.. because as I will show you, **it happens!


First of all, I'm writting this text as [removed] (my 2nd account) but the problem is with my main account that I use since 2009 ([removed]).
I´m writting it from this account because I dont have access to my main account.


I'm military and I was in comission out of my country for more or less 1 year and my cell phone carrier cancel my cell phone number because I didn´t pay the monthly value. Of course I knew that will happen but I dont want to pay every month +/- 20€ knowing that I will not use it.. (at this time I was using dropbox without any problem in the desktop).


The time pass and some months after, the Android release the version 7.0 and my system got the update and format the cell phone.


Well I install all of my apps and configure again my bank account because many of them had 2-factor activated. Of course I got some problems in some of them to prove my identity.. (but I sent my id card and mac addresses of the devices that were previous connected to that accounts and all got solve! and we are talking about real money...bank account!).

One of the apps that I reinstall was Dropbox. And I though: "well currently I´m not using it in my cell phone so I configure it later" (again, at this time I was using dropbox without any problem in the desktop)...


The time pass and 1 year after I formatted my computer.


When I was installing all the applications that I had before, I face the problem that I´m sharing with you today... I couldnt access to my Dropbox account because:


Problem 1 - Cell phone number. I no longer have this cell number because it got deactivated.

Reaction 1 - I contacted my old cell phone company and they cant reactivate it because it is beeing sell in some store of the country and they cant know the location of it now.


Problem 2 - I dont have any devices with the dropbox information saved

Reaction 2: But I still have my Sony Xperia Z5 Compact and my desktop that were the last devices to access in my account.


Problem 3 - Unfortunatelly (my mistake) I didnt´t save the emergency pin code correctly... I though the best place should be where I expect never to lose it.. Inside of the dropbox.. So I cant reach it now...

To solve this I have:

Solution 1:
My Dropbox account is connected to my Gmail account.
My Gmail account is connected to my Facebook account and Bank Accounts.
My Gmail account is connected to my Paypal account and eBay account.
Can send you or do a remote connection with Dropbox to prove my identity through logins or send you some data of my bank that had at that time that contacts. this method BUT if it is not enough:

Solution 2:
About my cell phone number I still have extracts of the bank including my personal data . I also have papers with monthly payments to my old number. Can send you to prove my identity too. But even this method isnt enough:

Solution 3:
I still have the devices that were connected in the past to my Dropbox account.
I have the security codes that you sent me to my old number with the codes. I have that messages in my inbox! I also can send you pictures of the mac address and imei of the cell phone or the computer.


Well as you can see I can prove easily my identity if you decide to help a costumer and stop writting me default answers that dont help this situation.


(For the Community I already sent a ticket were I put some information of the solutions that I propose but for now there isnt solution).


For the Dropbox helper that will read this, I know that this is only valid if I write it from the correct email address but as long as I can´t do that, I have this ticket that have many information about this problem.

 

Ticket: #8172606

 

I think the solution to this isnt to go through weekly trying to contact my old phone number in the hope that there is already a user to resend me the pin code... This is absurd.

  • Good morning Dropbox Users,

    I had lost the full access to my Dropbox account.

    I lost my cell phone number; the emergency codes; and all the devices that I had connected so I couldnt sign in.

     

    After "fighting" with many persons that work in the costumer service of Dropbox and persons, that are suppose to help here in the community, I finally got a solution and I want to share with you it.

     

    Remember this only works if you are the real owner of the account.

     

    Things you must have:

    1 - You must have a cell phone and/or another device where you had your account connected.

    2 - Contact costumer service through chat and explain the problem. Open a ticket. (you must create another account to chat ).

    3 - They will sent you a link to the email of your MAIN account. Follow the instructions.

    4 - Contact again costumer support using the ticket number and ask to talk with a supervisor and provide these informations:
    4.1 - Email of the account.
    4.2 - Full name on the account.
    4.3 - DTG (Date-Time Group) of the creation of the account.
    4.4 - The cell phone number associatted to your account.
    4.5 - Your actual city (where are you typing right now).
    4.6 - The city where you did the last successfully login into Dropbox.
    4.7 - The name of a file that you have recently uploaded to Dropbox.
    4.8 - The name of a folder that you have created into Dropbox.
    4.9 - The name of any person with whom you share a folder, AND the name of that shared folder?
    4.10 - The name of any linked computer?
    4.11 - Attach a picture of the mac address of the network card that you used the last time to connect to your Dropbox. (it can be a cell phone or computer).

     

    If you give those informations correctly they will check your situation, and if all its ok, they will sent you a link (that expire soon, so pay attention to the email address that you used to chat) that allows you to reset your password.

     

    Hope it allows to solve situations like i had before.

     

    For read my situation follow this link:
    https://www.dropboxforum.com/t5/Manage-account/Two-factor-problem-account-lost-user-since-2009/td-p/...

     

    This really works for me. Hope it helps the next users that pass through the same problem.

     

    I will follow this thread for help also who needs slightly smiling face

  • jdcchora's avatar
    jdcchora
    Helpful | Level 6

    Good morning Dropbox Users,

    I had lost the full access to my Dropbox account.

    I lost my cell phone number; the emergency codes; and all the devices that I had connected so I couldnt sign in.

     

    After "fighting" with many persons that work in the costumer service of Dropbox and persons, that are suppose to help here in the community, I finally got a solution and I want to share with you it.

     

    Remember this only works if you are the real owner of the account.

     

    Things you must have:

    1 - You must have a cell phone and/or another device where you had your account connected.

    2 - Contact costumer service through chat and explain the problem. Open a ticket. (you must create another account to chat ).

    3 - They will sent you a link to the email of your MAIN account. Follow the instructions.

    4 - Contact again costumer support using the ticket number and ask to talk with a supervisor and provide these informations:
    4.1 - Email of the account.
    4.2 - Full name on the account.
    4.3 - DTG (Date-Time Group) of the creation of the account.
    4.4 - The cell phone number associatted to your account.
    4.5 - Your actual city (where are you typing right now).
    4.6 - The city where you did the last successfully login into Dropbox.
    4.7 - The name of a file that you have recently uploaded to Dropbox.
    4.8 - The name of a folder that you have created into Dropbox.
    4.9 - The name of any person with whom you share a folder, AND the name of that shared folder?
    4.10 - The name of any linked computer?
    4.11 - Attach a picture of the mac address of the network card that you used the last time to connect to your Dropbox. (it can be a cell phone or computer).

     

    If you give those informations correctly they will check your situation, and if all its ok, they will sent you a link (that expire soon, so pay attention to the email address that you used to chat) that allows you to reset your password.

     

    Hope it allows to solve situations like i had before.

     

    For read my situation follow this link:
    https://www.dropboxforum.com/t5/Manage-account/Two-factor-problem-account-lost-user-since-2009/td-p/...

     

    This really works for me. Hope it helps the next users that pass through the same problem.

     

    I will follow this thread for help also who needs slightly smiling face

    • jdcchora's avatar
      jdcchora
      Helpful | Level 6

      Mark can you change the name of my topic? This one doesnt help to much right now.

       

      Change it to: "Recover Account with 2-FA active (solution)"


      Thanks

  • Jay's avatar
    Jay
    Icon for Dropbox Staff rankDropbox Staff
    Hi Joao, I removed your emails for security reasons.
     
    Regarding your issue, this is a very common factor when upgrading a phone or having the emergency backup code saved on Dropbox.
     
    The two-step verification scenario you’re experiencing is outlined in my article of the same topic.
     
    Unfortunately, without the emergency backup code, nothing can be done to regain access to your account. 
     
    Using your login with other services to verify your account can’t be used for ownership.
     
    Proof of purchase doesn’t help either, since paying for an account doesn’t constitute ownership of the account. Users pay for other people’s Plus/Professional accounts all the time. Does it mean that they also own that person’s data rightfully?
     
    Previous codes being sent to you as proof are also disregarded, since this is randomized and could still be obtained from a lost phone. If old codes could be used to access your current account, then there’s no point in the security.
     
    I can only reinterate what my article mentioned:
     

    2FA is special in that you are in control of your own security. Basically, you don’t trust that an email and password alone could secure your account, so you added 2FA. 
     
    For the same reason, we can’t reset your password for you just because you say you own your email address. Otherwise, what’s the point of the extra security?

    If the agent in the support ticket can’t assist any further, then it’s possible that all options have been exhausted.
     
    Sorry to be the bearer of bad news.
    • Mark's avatar
      Mark
      Icon for Super User II rankSuper User II
      Unfortunately you told Dropbox to not give anybody access to your account unless they had the 2FA details (i.e. the codes you should save when setting it up) or the mobile number. Its only reasonable that they adhere to that instruction and not give anybody access who does not have it. Pictures etc. are easily forged and faked - hence why you need to keep the security codes given.
      • joaochora's avatar
        joaochora
        Explorer | Level 4
        Mark I´m not talking about pictures.
        I work in cyber security and I know that are procedures to confirm the identity.. Its not about a picture its about a conversation or bank account details.. Forge this stuff is a crime.
    • joaochora's avatar
      joaochora
      Explorer | Level 4

      Well you are complicating what are so simple,

       

      Lets review Dropbox Policy Privacy:

      https://www.dropbox.com/privacy

       

      "Account information. We collect, and associate with your account, the information you provide to us when you do things such as sign up for your account, upgrade to a paid plan, and set up two-factor authentication (like your name, email address, phone number, payment info, and physical address). Some of our Services let you access your accounts and your information via other service providers."

       

      Well can you check if I have a physical address associatted to my dropbox? If I have, maybe you can resent me a code by postal service...

       

      "Contacts. You may choose to give us access to your contacts to make it easy for you to do things like share and collaborate on Your Stuff, send messages, and invite others to use the Services. If you do, we’ll store those contacts on our servers for you to use."

       

      I can provide many contacts of persons that entered in Dropbox through me. Only I know that right? That´s why I got almost 16gb of Dropbox..

       

      "Usage information. We collect information related to how you use the Services, including actions you take in your account (like sharing, editing, viewing, and moving files or folders). We use this information to improve our Services, develop new services and features, and protect Dropbox users. Please refer to our FAQ for more information about how we use this usage information to improve our Services."

       

      I can provide you informations about my folders. Only I know right? And as your terms say: "We use this information to improve our Services, develop new services and features, and protect Dropbox users". So maybe you can use it...

       

      "Device information. We also collect information from and about the devices you use to access the Services. This includes things like IP addresses, the type of browser and device you use, the web page you visited before coming to our sites, and identifiers associated with your devices. Your devices (depending on their settings) may also transmit location information to the Services."

       

      I need to say anything about this? I can provide you cell phone imei / mac addresses anything that you need. And this informations are related to devices that were previous connected in my dropbox account as I can see them in the trusted devices.

       

      Thanks.

       

       

      • Jay's avatar
        Jay
        Icon for Dropbox Staff rankDropbox Staff

        joaochora wrote: 

        "Account information. We collect, and associate with your account, the information you provide to us when you do things such as sign up for your account, upgrade to a paid plan, and set up two-factor authentication (like your name, email address, phone number, payment info, and physical address). Some of our Services let you access your accounts and your information via other service providers."

        Physical addresses aren't associated with accounts, unless you're on a Business account or using manual invoices, as they're able to customize invoices for themselves. Even then, this information can't be used to regain access.

         

        If this were the case, anyone could provide an address for a well-known company and ask for access to a random potential admin email, and if lucky, could get in.

         

        "Contacts. You may choose to give us access to your contacts to make it easy for you to do things like share and collaborate on Your Stuff, send messages, and invite others to use the Services. If you do, we’ll store those contacts on our servers for you to use."

        Note that it doesn't state that storing the contacts grants you to ability to access your account. If users could do that, we might have multiple accounts with the same contacts that could be breached.

         

        "Usage information. We collect information related to how you use the Services, including actions you take in your account (like sharing, editing, viewing, and moving files or folders). We use this information to improve our Services, develop new services and features, and protect Dropbox users. Please refer to our FAQ for more information about how we use this usage information to improve our Services."

        Again, this doesn't state you can use the information to help in regaining access to the account. What if your phone was taken and then they have access to the app? After verification of a few folders, the person could then take over your account entirely.

         

        "Device information. We also collect information from and about the devices you use to access the Services. This includes things like IP addresses, the type of browser and device you use, the web page you visited before coming to our sites, and identifiers associated with your devices. Your devices (depending on their settings) may also transmit location information to the Services."

        Once more, this cannot grant you access to the account, by simply knowing which devices you used to login to the app. Any person who has your devices could verify it very easily.

         

        While it does seem that this is strict, these are security policies put in place to secure your data from any access. Even if you could provide an ID card, there's no log of it in the system to compare it to since we never requested it to begin with.

         

        Only the emergency code can be used unfortunately.

  • alexmn1's avatar
    alexmn1
    New member | Level 2

    Hello,

    I am trying to access a 3-4 year old account. I have the account email, the password, and the 16 digit backup password. Is there a link i can goto to get account access without it first sending the 2fa to the old phone number. (A bypass with just the credentials i currently have?). I went to login and it said it sent the 2fa message but i didn't see another different field to enter the "emergency" 16 digit backup password. Thank you, -a

    • Rich's avatar
      Rich
      Icon for Super User II rankSuper User II

      alexmn1 wrote:

      ... i didn't see another different field to enter the "emergency" 16 digit backup password.


      From here: https://help.dropbox.com/accounts-billing/security/issues-two-step-verification

       

      Use your Dropbox emergency backup code

      You may have set an emergency backup code when you set up your Dropbox account. If you did, you were told to save it for your records. If you still have your backup code, click Having trouble getting a code? in the window that appears when you try to sign in, and then click Enter the emergency backup code and type in your code.

About Settings and Preferences

The Dropbox Community is here to help if you have questions about your account settings and preferences. Learn and share advice with members.

Need more support

If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X or Facebook.

For more info on available support options for your Dropbox plan, see this article.

If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!