AUTO-UPDATED

Dropbox breach seemingly caused by egregious authentication failure [U]

Dropbox has confirmed a security breach affecting approximately 5,000 user accounts, caused by a flaw in the single sign-on integration process between the cloud provider and Lenovo.

Key Points

  • Unauthorized access occurred between August 4 and August 21, 2026, with files downloaded from roughly 1,500 accounts.
  • The vulnerability stemmed from a Lenovo email verification process that allowed attackers to register accounts using victims' email addresses.
  • Dropbox failed to require secondary authentication or user consent when linking new Lenovo IDs to existing Dropbox accounts.
  • The company has since patched the security flaw and terminated all active sessions authenticated through the compromised Lenovo ID integration.
  • Users are strongly encouraged to enable two-factor authentication to protect their accounts from future unauthorized access attempts.

Why it Matters

This incident highlights the significant security risks associated with federated identity systems when platforms fail to implement rigorous account-linking protocols. It serves as a critical reminder for users to maintain multi-factor authentication, as even trusted third-party integrations can become vectors for unauthorized data access.
9to5Mac Published by Ben Lovejoy
Read original