Dropbox Compromised 5,000 Accounts Via Lenovo ID Authentication Flaw
Dropbox disclosed that approximately 5,000 user accounts were compromised in August due to attackers exploiting a weakness in its Lenovo ID sign-in integration.

Dropbox has revealed that around 5,000 customer accounts were compromised in August, stemming from an exploitation of a flaw within its integration with Lenovo ID for authentication. This incident underscores the security risks inherent when cloud services rely on third-party identity providers without robust, account-level verification.
The unauthorized access occurred between August 4 and August 21, 2026. Attackers successfully created Lenovo IDs using the email addresses of unsuspecting victims, exploiting a weakness in Lenovo's email verification process. These newly created Lenovo IDs were then used to log into Dropbox accounts associated with the same email addresses, bypassing the need for the victim's actual Dropbox password. This method of attack leveraged a federated authentication trust relationship rather than a direct breach of Dropbox credentials.
The vulnerability allowed an attacker to impersonate a Dropbox user by using a separately created Lenovo ID. The issue arose because Dropbox's system accepted a Lenovo identity that claimed control over an email address already linked to an existing Dropbox account. This created a pathway for account takeover, particularly affecting accounts that did not have Dropbox's two-factor authentication (2FA) enabled.
While Dropbox stated that attackers viewed and downloaded content from compromised accounts, individual user notifications indicated that in some cases, there was no evidence of files being accessed or downloaded. This suggests the impact and scope of the breach varied among the affected users. The incident is particularly concerning as victims did not necessarily need to have, create, or actively link a Lenovo ID to their Dropbox account to be exposed.
The core of the problem lay in the reliance on email addresses as a sole identifier across two distinct services, coupled with insufficient verification that the party registering the Lenovo ID genuinely controlled the associated mailbox. Security experts emphasize that matching email addresses alone should not be considered definitive proof of account ownership or identity linkage between different platforms.
In response, Dropbox has terminated all active sessions authenticated via Lenovo IDs and has severed the link between Lenovo ID and Dropbox accounts. Furthermore, the company has updated its login process to require users to enter their Dropbox password before they can access their account through Lenovo ID. Lenovo has acknowledged the issue, describing it as a "legacy integration" that could improperly authenticate certain Dropbox accounts and stated it is investigating the matter.
For end-users, this incident serves as a critical reminder of the importance of enabling two-factor authentication, even when using single sign-on or federated login services. Dropbox has advised affected customers to change their Dropbox passwords, secure their associated email accounts, and enable two-step verification. Users are also encouraged to review active sessions, connected applications, sharing links, recent file activity, and account recovery settings for any unauthorized changes.
From an enterprise security standpoint, this breach highlights the necessity for continuous review of identity provider integrations. Organizations should mandate phishing-resistant multi-factor authentication, rigorously verify external identity ownership before linking accounts, limit automatic account matching based solely on email claims, and implement robust monitoring for anomalous sign-ins originating from newly created or previously unseen federated identities.
The Register article provides additional detail on the timeline of the compromise, stating it occurred between August 4th and August 21st. It also highlights that fewer than a third of the affected users had any files accessed, and that none of the compromised accounts had two-factor authentication enabled. The report further notes that Dropbox has since severed the link between affected accounts and Lenovo.