< Back to all clusters
[TECHNOLOGY] · 21 sources

started · updated

Dropbox confirms breach of 5,000 accounts via Lenovo ID flaw

Dropbox has confirmed a security breach affecting approximately 5,000 user accounts. The unauthorized access occurred between August 4 and August 21, 2026.

Investigators identified the cause as a flaw in a legacy integration between Dropbox and Lenovo's Single Sign-On (SSO) system. A vulnerability in Lenovo’s email verification process allowed attackers to register fraudulent Lenovo IDs using victims' email addresses without needing access to their actual inboxes. Because Dropbox implicitly trusted these Lenovo IDs, hackers were able to bypass passwords and access associated Dropbox accounts, particularly those without two-factor authentication (2FA) enabled.

In less than one-third of the compromised cases, attackers were able to view or download stored files. Following the discovery, which was brought to light by security researcher Yoni Levy, Dropbox terminated all sessions authenticated via Lenovo ID and removed the integration. Users are now required to enter their Dropbox password when attempting to link accounts through Lenovo. Dropbox has reported the incident to data protection regulators, and the company's shares saw a decline following the announcement.

Entities

Dropbox · Lenovo · Yoni Levy

Sources

9 days ago
9 days ago