Back to Feed
BreachesSep 2, 2026

Dropbox accounts breached through Lenovo email verification flaw

Dropbox accounts accessed via flaw in Lenovo's email verification process.

Summary

Dropbox has alerted users to a security incident where unauthorized parties accessed accounts by exploiting a vulnerability in Lenovo's email verification system. Attackers registered fraudulent Lenovo IDs using victims' email addresses and then used these to log into associated Dropbox accounts. Approximately 5,000 accounts were affected, with some content being viewed and downloaded.

Full text

Dropbox accounts breached through Lenovo email verification flaw By Bill Toulas September 2, 2026 08:30 AM 0 Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs. Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to log into Dropbox accounts using verified Lenovo IDs. According to the notification sent to impacted users, the unauthorized access was possible due to "an issue with Lenovo's email verification process," which "allowed an unauthorized party to register a Lenovo ID using your email address." The attacker then used the fraudulent Lenovo ID to access the Dropbox account registered under the same email address without needing the login password. Dropbox’s identity-linking process trusted Lenovo’s assertion that the attacker controlled the email address without requiring confirmation through the existing Dropbox login method. “While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.” Dropbox's notice to impacted usersSource: @yonilevy Some Dropbox users reported receiving "about two weeks ago" notifications about suspicious Dropbox sign-ins and immediately changing their password and activating two-factor authentication (2FA). "One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID," user xaphod said. The cloud storage company determined that the attacker accessed users’ Dropbox accounts between August 4 and 21. In a statement for BleepingComputer, Lenovo said that the issue was related to a legacy integration between Lenovo ID and Dropbox, which could be leveraged "to improperly authenticate certain Dropbox accounts." "Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk," a Lenovo spokesperson told BleepingComputer. The investigation into the incident continues, but the company determined that Lenovo customers were not affected by the issue. Dropbox responded by expiring all sessions authenticated through Lenovo IDs and adding a new login requirement mandating that users enter their Dropbox account password when attempting to use Lenovo ID authentication. According to Reuters, approximately 5,000 accounts were accessed, and the hacker viewed and downloaded content from some users. BleepingComputer has contacted Dropbox for additional information, but we have not received a response as of publication. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Sakura Internet hack exposes data of up to 1.36 million accountsNovocure data breach affects more than 1,400 cancer patientsAesto Health says data breach affects over 9.5 million patientsBerlin confirms data theft after Rhysida ransomware attack claimsFulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Entities

Dropbox (product)Lenovo (vendor)Identity Provider Services (technology)