Particle.news
Download on the App Store

Dropbox Breach Tied to Lenovo SSO Flaw Compromises About 5,000 Accounts

A broken email‑verification step in a Lenovo sign‑on path let attackers open Dropbox sessions without passwords, exposing the fragility of third‑party login links.

Overview

  • Attackers exploited a Lenovo ID email‑verification flaw to register IDs using other people’s email addresses and then used those IDs to sign into linked Dropbox accounts between August 4 and August 21, 2026.
  • Dropbox says roughly 5,000 accounts were accessed and files were viewed or downloaded from about 1,500 of those accounts, with affected users notified directly by email.
  • The intrusion targeted accounts that did not have Dropbox two‑factor authentication enabled and did not require victims’ Dropbox passwords or access to their email inboxes.
  • Dropbox and Lenovo removed the Lenovo ID link, expired all Lenovo‑authenticated sessions, changed the login flow to require a Dropbox password before Lenovo sign‑ins, and have opened a joint investigation while regulators were notified.
  • The incident highlights the risk of legacy single‑sign‑on integrations and the protective value of multi‑factor authentication, and it prompted a short‑term drop in Dropbox shares though the company says it does not expect a material business impact.