< Back to all clusters
[TECHNOLOGY] · United States · 5 sources

started · updated

Dropbox security breach compromises 5,000 accounts via Lenovo ID flaw

Approximately 5,000 Dropbox accounts were compromised due to a security vulnerability involving Lenovo ID single sign-on (SSO) authentication. The unauthorized access occurred between August 4 and August 21, 2026.

The breach originated from a flaw in Lenovo’s email verification process during account registration. Attackers were able to create fraudulent Lenovo IDs using the email addresses of existing Dropbox users. Because of a legacy integration between the two services, Dropbox accepted these fraudulent Lenovo IDs as verified logins, allowing attackers to bypass standard password prompts and hijack accounts.

Data indicates that attackers successfully accessed or downloaded files from fewer than one-third of the compromised accounts. The vulnerability primarily affected users who had not enabled multi-factor authentication (MFA), as the presence of two-factor verification prevented takeovers for those users.

In response, Dropbox has terminated authenticated sessions via Lenovo ID, removed existing links between the services, and updated its processes to require Dropbox passwords for such integrations. Lenovo has characterized the issue as a problem related to a legacy integration and is continuing its investigation.

Entities

Dropbox · Lenovo