Dropbox Says Lenovo ID Flaw Compromised 5,000 Accounts

A Lenovo ID verification flaw let attackers compromise 5,000 Dropbox accounts without passwords. Learn what happened and how users can stay protected.

Sep 4, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Dropbox confirmed this week that attackers compromised roughly 5,000 user accounts during a 17-day intrusion between Aug. 4 and Aug. 21, 2026, with files viewed or downloaded in fewer than a third of them.

The attackers did not need victims’ Dropbox passwords or direct access to Dropbox’s servers. Instead, they exploited a weakness in Lenovo’s email verification process to register unauthorized Lenovo IDs using victims’ email addresses. Those identities could then be used to access the Dropbox accounts associated with the same addresses.

In notification emails sent to affected customers, Dropbox explained: “While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”

Dropbox spokesperson Tim Rathschmidt said the company promptly secured affected accounts and notified regulators, adding that Dropbox does not anticipate a material impact on its business. Lenovo described the connection as a “legacy integration” that “could be used to improperly authenticate certain Dropbox accounts,” noting that its own customers were not affected and an investigation is ongoing.

Behind the breach

The intrusion exposed a weakness in the companies’ authentication relationship: A Lenovo ID registered with a victim’s email address could access the associated Dropbox account without first requiring the victim’s Dropbox password.

Dropbox said none of the compromised accounts had two-factor authentication enabled. Its findings indicate that two-factor authentication would have provided another barrier against access through the fraudulent Lenovo IDs. In response, Dropbox severed active Lenovo ID connections, expired existing sessions, and added a safeguard requiring users to enter their native Dropbox password before completing any future Lenovo login.

The identity debt dilemma

The incident highlights a form of identity debt: legacy authentication integrations that remain active after their original security assumptions have aged. Cloud providers have long used single sign-on (SSO) and third-party login options to reduce friction, but these connections can create risk if organizations do not regularly audit, harden, or retire them.

Advertisement

When platforms treat external identifiers as proof of account ownership, weaknesses in a third-party identity provider can expose accounts on connected services. Even a strong Dropbox password could not prevent this attack because the legacy integration bypassed the normal Dropbox login process. Without periodic review and identity re-verification, trusted vendor connections can become overlooked account-takeover paths.

Protecting your cloud footprint

For businesses and consumers alike, relying solely on strong passwords is no longer enough when third-party pathways bypass them entirely.

To protect your cloud storage accounts:

  • Turn on MFA immediately: Enable multi-factor authentication across your cloud storage and primary email accounts to help block unauthorized access through single-factor authentication pathways.
  • Audit external access: Review your account settings to revoke unfamiliar active web sessions, third-party connected apps, and stale public sharing links.
  • Review account activity: Check recent sign-ins, active sessions, connected applications, shared links, and file activity for changes you do not recognize.

Dropbox has closed the Lenovo ID access path, but the broader lesson extends beyond one integration. Security teams should inventory external identity providers connected to corporate services, verify how accounts are matched, require MFA where possible, and retire login pathways that no longer serve a clear business need.

Read more: Infostealers are increasingly exposing enterprise SSO credentials and active sessions, showing how one compromised identity can provide access to multiple cloud services and corporate systems.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.