Dropbox Confirms 5,000 Accounts Compromised via Lenovo ID Flaw
Key Takeaways Approximately 5,000 Dropbox user accounts were compromised due to an exploited vulnerability in its Lenovo ID sign-in integration. Attackers leveraged a flaw in Lenovo’s email...
Key Takeaways
- Approximately 5,000 Dropbox user accounts were compromised due to an exploited vulnerability in its Lenovo ID sign-in integration.
- Attackers leveraged a flaw in Lenovo’s email verification process to create new Lenovo IDs using victims’ email addresses, then used these to access associated Dropbox accounts without needing the Dropbox password.
- The compromise occurred between August 4 and August 21, 2026, primarily affecting accounts that did not have Dropbox two-factor authentication enabled.
- Dropbox has since disabled Lenovo ID integration, forced password changes, and implemented stronger verification steps for future third-party logins.
Dropbox Accounts Compromised via Lenovo ID Integration Flaw
Cloud storage giant Dropbox has confirmed a security incident affecting approximately 5,000 user accounts. The breach, which occurred in August, stemmed from an exploit targeting a vulnerability within its integration with Lenovo ID for sign-in purposes. This event underscores the critical security implications when cloud platforms rely on third-party identity providers without robust, account-level validation mechanisms.
Table Of Content
Attack Vector and Impact
According to notifications sent to impacted users, unauthorized access took place over a period from August 4 to August 21, 2026. The attackers exploited a weakness in Lenovo’s email verification process, enabling them to register new Lenovo IDs using the email addresses of existing Dropbox users. With these newly established Lenovo identities, the threat actors could then log into the corresponding Dropbox accounts without requiring the victim’s Dropbox password.
This attack bypassed traditional password security by abusing a trusted federated authentication link. Dropbox’s system permitted users to log in with a verified Lenovo ID. However, the exploited workflow seemingly accepted a Lenovo identity that claimed ownership of an email address already linked to an existing Dropbox account. This created a pathway for account takeover, allowing an attacker to impersonate a Dropbox user through a fraudulent Lenovo ID.
Dropbox clarified that the affected accounts were those connected via Lenovo ID and notably lacked Dropbox’s two-factor authentication (2FA) protection. While Dropbox informed Reuters that content was viewed and downloaded from compromised accounts, individual user notifications indicated that in some cases, no evidence of file viewing or downloading was found. This discrepancy suggests varying degrees of impact among the affected user base. A key aspect of this incident is that victims might not have actively created or linked a Lenovo ID to become vulnerable.
The Root Cause: Email as a Sole Identifier
The core of the vulnerability lay in treating an email address as a sufficiently trusted identifier across two distinct services, without adequate verification that the party registering the Lenovo ID genuinely controlled the associated email inbox. In modern identity management systems, a matching email address alone should not be considered definitive proof that two accounts belong to the same individual, especially when linking services.
Mitigation and Future Security Measures
In response to the breach, Dropbox has taken several immediate and long-term actions. The company has terminated all active sessions authenticated through Lenovo IDs and has removed the association between Lenovo ID and Dropbox accounts. Furthermore, Dropbox has updated its login procedure, now requiring users to enter their Dropbox password before accessing an account via Lenovo ID, even if previously linked.
Lenovo, in notifications shared on X, acknowledged the issue stemmed from a “legacy integration” that could improperly authenticate certain Dropbox accounts and stated that an investigation is underway.
What You Should Do
- Change Passwords: Immediately update your Dropbox password to a strong, unique phrase. Also, change the password for the email account associated with your Dropbox account.
- Enable Two-Step Verification (2SV/MFA): Activate 2SV (also known as two-factor authentication or MFA) on your Dropbox account and all other critical online services. This adds a crucial layer of security beyond just a password.
- Review Account Activity: Check your Dropbox account for any unfamiliar active sessions, connected third-party applications, shared links, recent file activity, or changes to account recovery settings.
- Educate Yourself: Understand the risks of federated logins and the importance of strong, unique passwords and multi-factor authentication across all your online accounts.
- Enterprise Considerations: Organizations should regularly review identity provider integrations, mandate phishing-resistant MFA, rigorously verify ownership before linking external identities, and avoid automatic account matching based solely on email claims. Monitoring for anomalous sign-ins from newly created or previously unseen federated identities is also crucial.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.