Dropbox accounts breached through Lenovo email verification flaw

Published September 2, 2026

Dropbox says an attacker broke into about 5,000 accounts by abusing a flaw in Lenovo's identity system, not by stealing Dropbox passwords. The attacker registered a Lenovo ID using a victim's email address, then used that fake Lenovo ID to sign into their Dropbox account and view or download files.

Report priority
Medium
Involves
Dropbox

What is known

Dropbox lets people log in using a Lenovo ID because it connects to Lenovo's identity service behind the scenes, and Lenovo's email verification did not properly confirm that a person registering a new Lenovo ID actually controlled that email address, so an attacker could claim someone else's email, get a working Lenovo ID for it, and Dropbox trusted that...

What to do

Check your email and Dropbox notifications for a message from Dropbox about suspicious sign-ins or Lenovo ID activity between August 4 and August 21, 2026. Dropbox says roughly 5,000 accounts were accessed and some had files viewed or downloaded.

Dropbox has expired all sessions that logged in through Lenovo IDs and now requires your Dropbox password even when signing in via Lenovo ID, so change your Dropbox password, turn on two-factor authentication, and review your account's recent login history and connected apps.

Reported details

An attacker signs up for a Lenovo ID using a victim's email address, and Lenovo's verification does not catch that the attacker does not control that inbox. The attacker then goes to Dropbox and logs in with that Lenovo ID instead of a Dropbox password. Dropbox links the Lenovo ID to the matching email and lets the attacker straight into that person's account, where they view and download files.

Dropbox integrates with Lenovo Identity Provider Services so users can authenticate via a Lenovo ID. A flaw in Lenovo's email verification during Lenovo ID registration let an attacker claim a victim's email address without proving control of it. Dropbox's account-linking logic then trusted Lenovo's assertion of email ownership and authenticated the matching Dropbox account without re-checking the Dropbox password.

Lenovo describes this as a legacy integration issue between Lenovo ID and Dropbox. Dropbox's fix expires Lenovo ID sessions and now requires the Dropbox password as a second factor during Lenovo ID sign-in. Lenovo says its own customer accounts were not affected.