Dropbox confirmed this week that attackers compromised roughly 5,000 user accounts during a 17-day intrusion between Aug. 4 and Aug. 21, 2026, with files viewed or downloaded in fewer than a third of them.
The attackers did not need victims’ Dropbox passwords or direct access to Dropbox’s servers. Instead, they exploited a weakness in Lenovo’s email verification process to register unauthorized Lenovo IDs using victims’ email addresses. Those identities could then be used to access the Dropbox accounts associated with the same addresses.
In notification emails sent to affected customers, Dropbox explained: “While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
Dropbox spokesperson Tim Rathschmidt said the company promptly secured affected accounts and notified regulators, adding that Dropbox does not anticipate a material impact on its business. Lenovo described the connection as a “legacy integration” that “could be used to improperly authenticate certain Dropbox accounts,” noting that its own customers were not affected and an investigation is ongoing.
Behind the breach
The intrusion exposed a weakness in the companies’ authentication relationship: A Lenovo ID registered with a victim’s email address could access the associated Dropbox account without first requiring the victim’s Dropbox password.
Dropbox said none of the compromised accounts had two-factor authentication enabled. Its findings indicate that two-factor authentication would have provided another barrier against access through the fraudulent Lenovo IDs. In response, Dropbox severed active Lenovo ID connections, expired existing sessions, and added a safeguard requiring users to enter their native Dropbox password before completing any future Lenovo login.
The identity debt dilemma
The incident highlights a form of identity debt: legacy authentication integrations that remain active after their original security assumptions have aged. Cloud providers have long used single sign-on (SSO) and third-party login options to reduce friction, but these connections can create risk if organizations do not regularly audit, harden, or retire them.
When platforms treat external identifiers as proof of account ownership, weaknesses in a third-party identity provider can expose accounts on connected services. Even a strong Dropbox password could not prevent this attack because the legacy integration bypassed the normal Dropbox login process. Without periodic review and identity re-verification, trusted vendor connections can become overlooked account-takeover paths.
Protecting your cloud footprint
For businesses and consumers alike, relying solely on strong passwords is no longer enough when third-party pathways bypass them entirely.
To protect your cloud storage accounts:
- Turn on MFA immediately: Enable multi-factor authentication across your cloud storage and primary email accounts to help block unauthorized access through single-factor authentication pathways.
- Audit external access: Review your account settings to revoke unfamiliar active web sessions, third-party connected apps, and stale public sharing links.
- Review account activity: Check recent sign-ins, active sessions, connected applications, shared links, and file activity for changes you do not recognize.
Dropbox has closed the Lenovo ID access path, but the broader lesson extends beyond one integration. Security teams should inventory external identity providers connected to corporate services, verify how accounts are matched, require MFA where possible, and retire login pathways that no longer serve a clear business need.
Read more: Infostealers are increasingly exposing enterprise SSO credentials and active sessions, showing how one compromised identity can provide access to multiple cloud services and corporate systems.





