← Dropbox

2026 Dropbox — ~5,000 accounts via Lenovo ID email-verification flaw (Aug 4–21 SSO bypass)

2026 5.0K records affected Share on X

Data compromised

Approximately 5,000 Dropbox accounts accessed; Reuters reports content viewed/downloaded from some accounts; no passwords required when using fraudulent Lenovo ID per Dropbox notices

Technical writeup

Verified Dropbox customer notices — September 2, 2026. Dropbox warned users that between August 4 and August 21, 2026 an unauthorized party exploited a flaw in Lenovo’s email verification for Lenovo ID registrations used in Dropbox’s SSO authentication path. Attackers registered Lenovo IDs on victims’ email addresses without controlling those inboxes, then logged into associated Dropbox accounts without Dropbox passwords. Dropbox expired Lenovo-ID sessions and now requires Dropbox passwords when using Lenovo SSO; Lenovo said the issue involved a legacy integration and that Lenovo customers were not affected. Reuters cited ~5,000 compromised accounts with some files viewed or downloaded. recordsAffected 5000 from Reuters/Dropbox; companyConfirmed true.

Root cause

Lenovo legacy Dropbox SSO integration let attackers register fraudulent Lenovo IDs using victims’ emails without verification, then authenticate into linked Dropbox accounts Aug 4–21, 2026

References