Dropbox security breach exposed 5,000 accounts via Lenovo ID flaw

NewsTue, 01 Sep 2026 23:57:05 UTC4 hours ago
Dropbox security breach exposed 5,000 accounts via Lenovo ID flaw

A cloud storage account is supposed to feel like a locked drawer. But for roughly 5,000 Dropbox users, that drawer opened without anyone typing a password. The Dropbox security breach that came to light this week traces back to an unlikely source: a flawed sign-in system tied to Lenovo, the computer maker, which let attackers slip into accounts by simply claiming someone else’s email address.

Key takeaways

  • Attackers exploited a Lenovo ID authentication flaw to access Dropbox accounts without needing victims’ passwords.
  • Unauthorized access took place between August 4 and August 21, 2026, according to Dropbox.
  • About 5,000 Dropbox accounts were impacted, and less than a third had files viewed or downloaded.
  • Only accounts without Dropbox’s two-factor authentication enabled were vulnerable.
  • Dropbox has changed how Lenovo IDs can connect to accounts and emailed every affected user directly.

How the Lenovo ID Authentication Flaw Let Hackers In

The breach didn’t start with stolen passwords or a hacked server. It started with a gap in how Lenovo verified email ownership. Dropbox offers Lenovo ID as a single sign-on, or SSO, option, letting users log in through a verified Lenovo identity instead of a Dropbox password. That convenience became the entry point attackers needed.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related