Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration.
The incident highlights the security risks that can arise when cloud platforms trust third-party identity providers without requiring strong, account-level verification before granting access.
According to notifications sent to affected users, unauthorized access occurred between August 4 and August 21, 2026. Dropbox said attackers were able to register Lenovo IDs using victims’ email addresses due to an issue in Lenovo’s email-verification process.
The attackers could then use those newly created identities to sign in to Dropbox accounts associated with the same email address, without needing the victim’s Dropbox password.
The attack appears to have abused a federated authentication trust relationship rather than a conventional password breach. Dropbox allows users to log in with verified Lenovo IDs, but the affected workflow apparently accepted a Lenovo identity asserting control of an email address that was already tied to an existing Dropbox account.
This created an account-takeover path in which an attacker could impersonate a Dropbox user through a separately created Lenovo ID.
Dropbox said the impacted accounts were connected through Lenovo ID and did not have Dropbox two-factor authentication enabled.
The company told Reuters that attackers viewed and downloaded content from compromised accounts, while user-specific notifications state that Dropbox found no evidence that files were viewed or downloaded in at least some individual cases.
The distinction suggests the scope and impact varied across the affected population. The incident is notable because victims may not have needed to possess, create, or actively link a Lenovo ID to become exposed.
The core issue was the use of an email address as a trusted identifier across two services, combined with insufficient proof that the party registering the Lenovo ID actually controlled the corresponding mailbox.
In identity systems, matching email addresses alone should not be treated as conclusive proof that two accounts belong to the same person.
Dropbox has since terminated all sessions authenticated through Lenovo IDs, removed the association between Lenovo ID and Dropbox accounts, and changed its login process so that users must enter their Dropbox password before accessing an account through Lenovo ID.
As detailed in notifications shared on X, Lenovo described the issue as involving a “legacy integration” that could improperly authenticate certain Dropbox accounts and said it was investigating.
For users, the incident reinforces the importance of enabling two-factor authentication even when a service supports single sign-on or federated login.
Dropbox advised affected customers to change their Dropbox password, change the password for their email account, and turn on two-step verification.
Users should also review active sessions, connected applications, sharing links, recent file activity, and account-recovery settings for unfamiliar changes. From an enterprise security perspective, the breach is a reminder that identity-provider integrations require continuous review.
Organizations should require phishing-resistant MFA, verify ownership before linking external identities, limit automatic account matching based solely on email claims, and monitor anomalous sign-ins from newly created or previously unseen federated identities.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw appeared first on Cyber Security News.
