Dropbox Accounts Compromised Through Lenovo ID Authentication Flaw
Around 5,000 Dropbox accounts were compromised in August after attackers exploited a flaw in the way Dropbox accepted Lenovo IDs for single sign-on access.
The incident allowed attackers to create Lenovo accounts using other users’ email addresses and use those accounts to enter linked Dropbox accounts without knowing the victims’ Dropbox passwords.
How The Lenovo ID Flaw Opened Dropbox Accounts
The breach centred on an old integration between Dropbox and Lenovo ID, Lenovo’s login system for its products and services.
Dropbox allows users to access an account through a verified Lenovo ID.
However, an issue in Lenovo’s email verification process meant attackers could register Lenovo IDs using email addresses belonging to Dropbox users, including people who had never created Lenovo accounts.
Those newly created Lenovo IDs could then be used to authenticate against Dropbox accounts associated with the same email addresses.
The affected Dropbox accounts did not have two-factor authentication enabled, removing an additional security check that could have stopped the unauthorised logins.
The attackers therefore did not appear to need victims’ Dropbox passwords or access to their email inboxes.
About 5,000 Accounts Were Compromised
Dropbox said around 5,000 accounts were compromised between 4 August and 21 August 2026.
Files were accessed in fewer than a third of those accounts, with some users told that material had been viewed and downloaded, while other affected customers were told there was no evidence that their files had been accessed.
The difference was reflected in notification emails sent to users by Dropbox on 31 August.
Dropbox spokesperson Tim Rathschmidt said the company moved to secure affected accounts after discovering the issue, notified affected users and reported the incident to data protection regulators.
The company also said it did not expect the breach to have a material impact on its business.
A Login From The UK Raised The Alarm
One affected user, developer Yoni Levy, shared screenshots of Dropbox’s notification on X after receiving an alert about a new browser login.
The alert showed a Chrome session on Windows from “Near Canary Wharf, England, United Kingdom” at 6:06 a.m. on 18 August.
Levy said he had never created a Lenovo account and had not travelled to the UK.
A later message from Dropbox explained that an unauthorised party had registered a Lenovo ID using his email address and then used it to access his Dropbox account.
The case illustrates how the flaw could allow an attacker to bypass the usual password route while still appearing to Dropbox as an authenticated Lenovo user.
Dropbox Removes Lenovo Access From Accounts
Dropbox has since terminated sessions authenticated through Lenovo ID and removed the links between Lenovo IDs and Dropbox accounts.
The company also changed its systems so that users must enter their Dropbox password before accessing an account through Lenovo.
These measures are intended to prevent the same authentication route from being used again.
Lenovo Calls It A Legacy Integration Issue
Lenovo confirmed that it had identified a problem involving what it described as a “legacy integration” between Lenovo ID and Dropbox.
The company said the integration “could be used to improperly authenticate certain Dropbox accounts”.
Lenovo said its customers were not affected and that it was working with Dropbox to “mitigate the risk”, while its investigation remains ongoing.
The incident also affected Dropbox investors, with the company’s shares falling as much as 6.6 per cent in post-market trading on 1 September before the decline narrowed in later trading.