Dropbox Breach: 5,000 Accounts Affected via Lenovo Login
Dropbox has reported that 5,000 accounts were breached due to a security flaw involving a Lenovo login. This occurred between August 4 and 21, 2026, according to Dropbox.
The Vulnerability
The issue stemmed from a legacy integration between Lenovo ID and Dropbox that failed to properly verify email ownership. An attacker could register a Lenovo ID using a stranger’s email address and subsequently access the victim’s Dropbox account without needing their password.
Impact and Mitigation
- Affects: Approximately 3,500 accounts were accessed without any files being taken, suggesting automated access rather than targeted file theft.
- Multi-factor Authentication (MFA): Every compromised account lacked MFA. Dropbox emphasizes that MFA would have prevented the attack.
- Remediation: Lenovo identified and fixed the issue on its side. Dropbox terminated all sessions authenticated through Lenovo ID, disabled the integration, and now requires a native Dropbox password for access.
Regulatory and Practical Implications
- GDPR Notification: Both companies have reported the incident to data protection regulators, triggering GDPR notification obligations, including a 72-hour deadline for European users.
- Enterprise Impact: The incident highlights the risks associated with legacy single sign-on (SSO) integrations. Companies using SSO through external hardware vendors may be unaware of all the external integrations their accounts trust. Attackers have previously exploited similar weaknesses.
What’s Next?
Affected users were notified on Monday. The incident serves as a reminder to review and update legacy security integrations to prevent similar future breaches.