Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 7 sources · 3 days · First seen · Last updated
Dropbox account compromise via Lenovo ID vulnerability
Overview
Between August 4 and August 21, 2026, approximately 5,000 Dropbox accounts were compromised due to a security vulnerability involving a legacy integration with Lenovo ID single sign-on (SSO) authentication.
The breach exploited a flaw in Lenovo’s email verification process during account registration, which allowed attackers to create fraudulent Lenovo IDs using the email addresses of existing Dropbox users. Because of the integration, Dropbox accepted these IDs as verified logins, enabling attackers to bypass standard password prompts. The vulnerability primarily impacted users who had not enabled multi-factor authentication (MFA) or two-factor authentication (2FA).
Evidence indicates that attackers successfully accessed or downloaded files from fewer than one-third of the compromised accounts. In response, Dropbox has terminated authenticated sessions via Lenovo ID, removed the service links, and updated its processes to require Dropbox passwords for such integrations. Lenovo has characterized the incident as a problem related to a legacy integration and is continuing its investigation.
Entities
Timeline
-
5 days ago
[TECHNOLOGY] 2 sourcesDropbox accounts compromised via Lenovo ID vulnerabilityHackers accessed roughly 5,000 Dropbox accounts by exploiting a flaw in Lenovo’s email verification process, allowing unauthorized logins via Lenovo IDs without a Dropbox password.
-
8 days ago
[TECHNOLOGY] 5 sourcesDropbox security breach compromises 5,000 accounts via Lenovo ID flawA security flaw in Lenovo ID's authentication allowed attackers to hijack approximately 5,000 Dropbox accounts by exploiting a legacy single sign-on integration between August 4 and 21, 2026.
Sources
diarioti.com · elnacional.cat · grahamcluley.com · ipadizate.es · saferworld.org.uk · ubergizmo.com · wwwhatsnew.com