Lenovo ID flaw exposes 5,000 Dropbox accounts
Attackers found a weakness in how Lenovo verifies email addresses for its Lenovo ID accounts and used it to register fake Lenovo IDs tied to victims' email addresses. Because Dropbox lets people sign in with a linked Lenovo ID, this let the attackers into about 5,000 Dropbox accounts over a 17 day window without needing the victims' Dropbox passwords. Dropbox says files were viewed or downloaded in fewer than a third of the affected accounts.
- Started
- Aug 4, 2026
- Latest activity
- Sep 7, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States
- Sectors
- Technology, Consumers
- Scale
- about 5,000 Dropbox user accounts
Current status
A September 7 report said Dropbox terminated Lenovo-authenticated sessions and now requires Dropbox passwords for Lenovo ID sign-ins.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Impact
Attackers accessed roughly 5,000 Dropbox accounts and viewed or downloaded files in fewer than a third of them, without needing victims' Dropbox passwords or breaching Dropbox's own servers.
What to do
If you use Lenovo ID sign-in with Dropbox, reset your Dropbox and email passwords, check your Dropbox account activity log, turn on two-factor authentication, and watch for a notification email from Dropbox about this incident.
Timeline
-
Sep 7, 2026
Bitdefender reported that Dropbox terminated all sessions authenticated through Lenovo ID and now requires users to enter their actual Dropbox password when signing in through Lenovo ID. Lenovo said its customers and systems were unaffected, and Dropbox and Lenovo had worked together to mitigate the risk.
Containedbitdefender.com -
Sep 2, 2026
Dropbox began notifying affected users and more detail on the 17 day intrusion window became public.
Containedbleepingcomputer.com -
Aug 17, 2026
Dropbox confirmed the intrusion had compromised roughly 5,000 accounts via a Lenovo ID email verification flaw.
Containedesecurityplanet.com
Sources
- Lenovo ID flaw exposed 5,000 Dropbox accounts eSecurityPlanet Aug 17, 2026
- Dropbox accounts breached through Lenovo email verification flaw BleepingComputer Sep 2, 2026
- Dropbox says 5,000 accounts compromised in Lenovo ID security breach The American Bazaar Sep 2, 2026
- How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Bitdefender Sep 7, 2026
- Thousands of Dropbox accounts breached via Lenovo flaw Computing Sep 3, 2026 unverified