Overview
- Attackers exploited a Lenovo ID email‑verification flaw to register IDs using other people’s email addresses and then used those IDs to sign into linked Dropbox accounts between August 4 and August 21, 2026.
- Dropbox says roughly 5,000 accounts were accessed and files were viewed or downloaded from about 1,500 of those accounts, with affected users notified directly by email.
- The intrusion targeted accounts that did not have Dropbox two‑factor authentication enabled and did not require victims’ Dropbox passwords or access to their email inboxes.
- Dropbox and Lenovo removed the Lenovo ID link, expired all Lenovo‑authenticated sessions, changed the login flow to require a Dropbox password before Lenovo sign‑ins, and have opened a joint investigation while regulators were notified.
- The incident highlights the risk of legacy single‑sign‑on integrations and the protective value of multi‑factor authentication, and it prompted a short‑term drop in Dropbox shares though the company says it does not expect a material business impact.