Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Dropbox Breach Compromises 5,000 Accounts via Lenovo ID Flaw

Published 2 September 2026

Approximately 5,000 Dropbox accounts were compromised in a security breach that exploited a flaw in a single sign-on integration with Lenovo, the companies confirmed. The unauthorized access occurred over a three-week period from August 4 to August 21, 2026, with affected users notified by email on September 1. The breach did not involve stolen passwords or a direct hack of Dropbox's servers. Instead, attackers took advantage of a weakness in how Lenovo verified email addresses for its ID system. Dropbox offered a single sign-on option allowing users to log in using a verified Lenovo ID. According to Dropbox, an issue with Lenovo's email verification process allowed malicious actors to register new Lenovo IDs using victims' email addresses without proving they controlled those inboxes. Attackers could then use these fraudulent Lenovo IDs to log directly into the associated Dropbox accounts, bypassing the need for a password. Dropbox stated that only accounts linked to a Lenovo ID and without two-factor authentication enabled were vulnerable.

0:00 / 0:00