Dropbox has confirmed a security breach affecting approximately 5,000 user accounts, caused by a flaw in the single sign-on integration process between the cloud provider and Lenovo.
Key Points
- Unauthorized access occurred between August 4 and August 21, 2026, with files downloaded from roughly 1,500 accounts.
- The vulnerability stemmed from a Lenovo email verification process that allowed attackers to register accounts using victims' email addresses.
- Dropbox failed to require secondary authentication or user consent when linking new Lenovo IDs to existing Dropbox accounts.
- The company has since patched the security flaw and terminated all active sessions authenticated through the compromised Lenovo ID integration.
- Users are strongly encouraged to enable two-factor authentication to protect their accounts from future unauthorized access attempts.