
Dropbox Confirms ~5,000 Accounts Accessed via Lenovo ID SSO Flaw in August 2026
Corroborated reports detail a targeted Dropbox account access incident exploiting Lenovo ID verification and legacy SSO, affecting ~5k accounts with limited data exfiltration; companies have patched the integration.
Multiple credible reports confirm that Dropbox notified approximately 5,000 users of unauthorized access to their accounts between August 4 and August 21, 2026. Attackers exploited a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs using victims' email addresses, then leveraged a legacy single sign-on (SSO) integration between Lenovo ID and Dropbox to authenticate without the Dropbox password or email access. Most affected accounts lacked Dropbox two-factor authentication. Dropbox and Lenovo collaborated to mitigate the issue by expiring Lenovo-authenticated sessions, severing the legacy links, and requiring Dropbox passwords for future Lenovo ID logins. Files were viewed or downloaded in fewer than one-third of cases. The incident has been reported to regulators, and Lenovo stated its own customers were unaffected. This highlights risks in federated identity systems where email verification assumptions can be bypassed.
Security researchers: Legacy third-party SSO integrations continue to create silent attack surfaces that bypass standard password and 2FA protections, underscoring the need for stricter verification in federated auth flows.
Sources (5)
- [1]Dropbox accounts breached through Lenovo email verification flaw(https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/)
- [2]Dropbox says about 5,000 accounts compromised in August hack(https://www.reuters.com/technology/dropbox-says-about-5000-accounts-compromised-august-hack-2026-09-02/)
- [3]Hacker Breaches Dropbox Accounts Via Lenovo ID System(https://www.pcmag.com/news/hacker-breaches-dropbox-accounts-via-lenovo-id-system)
- [4]Dropbox Lenovo Breach Let Hackers Access 5,000 Accounts Without Passwords(https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/)
- [5]Legacy Lenovo login opens 5,000 Dropbox accounts to attackers(https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924)