Security leaks happen. The lesson here is treat anything that you put on a machine you don't completely control as being at-risk, even if you pay for top notch security and the vendor guarantees it. The guarantee (and any compensation) isn't a lot of comfort if the information hits the wild. This includes everything from web servers on Amazon to your Gmail account.
In the case of Dropbox, I would suggest PGP or Truecrypt anything sensitive and keep the keys locally or in another location that is completely unrelated to the box.
I'm going to change my behavior, the only things that go on Dropbox now will be completely public. They've completely lost my trust.