Dropbox accounts breached through Lenovo email verification flaw

Dropbox users are facing a security breach that allows unauthorized access to their accounts through a flaw in Lenovo’s email verification process. The cloud storage provider has warned its users that an attacker exploited this vulnerability to register fraudulent Lenovo IDs and gain access to Dropbox accounts without needing the login password.

The issue affects Dropbox users who have enabled the “Continue with SSO” feature, which allows them to log into their accounts using a verified ID from another service – in this case, Lenovo. Although some affected users may not have a Lenovo account, they still had their email address registered with the company, making it possible for an attacker to create a fraudulent Lenovo ID and access their Dropbox account.

Here’s what happened: when a user tries to log into their Dropbox account using a verified Lenovo ID, the system trusts Lenovo’s assertion that the email address is controlled by the user. However, if an attacker can register a Lenovo ID using the victim’s email address, they can then use that ID to access the associated Dropbox account without needing the login password. This process takes advantage of a weakness in Lenovo’s email verification process, which allows unauthorized parties to create fake IDs.

The breach was discovered when some users received notifications about suspicious sign-ins and changed their passwords immediately. Dropbox has since confirmed that the attacker accessed user accounts between August 4 and 21, with around 5,000 accounts compromised. In some cases, the hacker viewed and downloaded content from users’ accounts.

Lenovo has acknowledged the issue, stating that it was related to a legacy integration between Lenovo ID and Dropbox. The company says it worked collaboratively with Dropbox to mitigate the risk and expiried all sessions authenticated through Lenovo IDs. To prevent similar incidents in the future, Dropbox now requires users to enter their account password when attempting to use Lenovo ID authentication.

This incident highlights the importance of keeping your login credentials secure and monitoring your account activity regularly. Even if you don’t have a Lenovo account, it’s still possible for an attacker to create a fraudulent ID using your email address. To protect yourself, make sure to enable two-factor authentication (2FA) on all accounts and keep your passwords unique and strong. Regularly review your account activity and report any suspicious signs to the relevant services immediately.


Source: Bleeping Computer — 2026-09-02