Skip to content

164news.com

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Dropbox says 5,000 accounts were breached through a Lenovo login

Posted on September 2, 2026September 2, 2026 By Emily Chen No Comments on Dropbox says 5,000 accounts were breached through a Lenovo login

Dropbox Breach: 5,000 Accounts Affected via Lenovo Login

Dropbox has reported that 5,000 accounts were breached due to a security flaw involving a Lenovo login. This occurred between August 4 and 21, 2026, according to Dropbox.

The Vulnerability

The issue stemmed from a legacy integration between Lenovo ID and Dropbox that failed to properly verify email ownership. An attacker could register a Lenovo ID using a stranger’s email address and subsequently access the victim’s Dropbox account without needing their password.

Impact and Mitigation

  • Affects: Approximately 3,500 accounts were accessed without any files being taken, suggesting automated access rather than targeted file theft.
  • Multi-factor Authentication (MFA): Every compromised account lacked MFA. Dropbox emphasizes that MFA would have prevented the attack.
  • Remediation: Lenovo identified and fixed the issue on its side. Dropbox terminated all sessions authenticated through Lenovo ID, disabled the integration, and now requires a native Dropbox password for access.

Regulatory and Practical Implications

  • GDPR Notification: Both companies have reported the incident to data protection regulators, triggering GDPR notification obligations, including a 72-hour deadline for European users.
  • Enterprise Impact: The incident highlights the risks associated with legacy single sign-on (SSO) integrations. Companies using SSO through external hardware vendors may be unaware of all the external integrations their accounts trust. Attackers have previously exploited similar weaknesses.

What’s Next?

Affected users were notified on Monday. The incident serves as a reminder to review and update legacy security integrations to prevent similar future breaches.

Clock

Post navigation

Previous Post: PwC projects that the global investment in AI infrastructure will reach $31.6 trillion by 2050
Next Post: OpenAI says its next model finds security flaws nobody has found yet

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Hot Stories

  • Denver Plumbing for Renters
  • Plumber for Restaurant Installations Denver
  • 24/7 Plumber Available in Denver
  • Denver Water Softener Installation
  • Clock
  • Thyroid Test
  • sailboat
  • Steam Boat
  • Submarine
  • Catamaran

Recent Posts

  • Hegseth Targets 7 More Officers as His Frustrated Army Secretary Quits
  • Have You Felt Any Impact From Trump’s ‘Big Beautiful Bill’? Tell Us How.
  • On Trump’s Ballroom, Chief Justice Finds Himself in an Unusual Spot: In Dissent
  • Waymo opens driverless rides in Denver, San Diego and Tampa
  • Toyota’s FSD-Like System Arrives In 2028, But The Driver Stays Liable

Recent Comments

  1. sam86club on Massachusetts Police Search for Karen Solomon in Connection to Husband’s Death
  2. bet339download on AI-drafted bills are swamping the House office that writes US laws
  3. mxgoldrushcasino on Trump Fired His Inspectors General. Their Replacements Have a Different Mission.
  4. 7vvbetgame on Trump’s Immigration Policy Echoes 1920s Crackdown, but This Time Congress Isn’t Involved
  5. okttcasino on Alphabet raises A$5.5bn in Australia, more than doubling a record Apple set in 2015

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026

Hot Stories

  • Denver Plumbing for Renters
  • Plumber for Restaurant Installations Denver
  • 24/7 Plumber Available in Denver
  • Denver Water Softener Installation
  • Clock
  • Thyroid Test
  • sailboat
  • Steam Boat
  • Submarine
  • Catamaran

Copyright © 2026 164news.com.

Powered by PressBook Dark WordPress theme