Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw
Brief
Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration.
The incident highlights the security risks that can arise when cloud platforms trust third-party identity providers without requiring strong, account-level verification before granting access.
According to notifications sent to affected users, unauthorized access occurred between August 4 and August 21, 2026. Dropbox said attackers were able to register Lenovo IDs using victims’ email addresses due to an issue in Lenovo’s email-verification process.
The attackers could then use those newly created identities to sign in to Dropbox accounts associated with the same email address, without needing the victim’s Dropbox password.
