Dropbox says 5,000 accounts were breached through a Lenovo login

https://media.thenextweb.com/2026/09/Dropbox-logo.jpg

Somebody registered a Lenovo ID using a stranger’s email address and then used it to sign into that person’s Dropbox account without needing their password. About 5,000 accounts were compromised between August 4 and 21, Dropbox said.

The flaw was in a legacy integration between Lenovo ID and Dropbox that did not properly verify email ownership. Registering an account with someone else’s address was enough to authenticate as that person.

Files were viewed or downloaded in fewer than a third of the affected accounts. That means roughly 3,500 accounts were accessed without anything being taken, although the numbers alone do not show whether attackers were looking for specific files or simply accessing accounts automatically.

Every compromised account lacked multi-factor authentication. Dropbox has been clear about that, and it is probably the most useful detail for anyone looking at what could have prevented the attack.

Lenovo identified the integration on...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more