A security vulnerability involving Lenovo ID single sign-on authentication resulted in unauthorized access to approximately 5,000 Dropbox accounts. The cloud storage provider notified affected individuals by email, confirming that unauthorized activity was detected on impacted accounts between August 4 and August 21, 2026. 

The security breakdown occurred due to an email verification flaw within Lenovo’s account registration system. Attackers discovered they could create a fraudulent Lenovo ID using a targeted victim’s existing email address without proper identity confirmation. Because of a legacy authentication integration between the two platforms, Dropbox treated the newly created Lenovo ID as a verified login for the associated Dropbox profile. This oversight allowed the hacker to bypass standard credential prompts and directly hijack existing accounts simply by knowing the user’s primary email address. 

The incident drew sharp criticism from cybersecurity observers, who highlighted the fundamental flaw of permitting third-party login linking to pre-existing user accounts without demanding proof of prior password ownership. The breach raised immediate privacy concerns given that Dropbox users routinely host personal documents, financial data, and sensitive corporate files on the platform. 

Despite the severity of the authentication oversight, the impact remained relatively isolated. Reports indicate that around 5,000 accounts were accessed, none of which had enabled multi-factor authentication (MFA). The presence of two-factor verification successfully prevented account takeovers against users who had configured it. 

In response, Lenovo characterized the vulnerability as an issue tied to a legacy integration, stating that both organizations collaborated to resolve the underlying authentication process. To remediate the threat, Dropbox took immediate containment actions: 

  • Terminated and expired all active sessions that were authenticated via Lenovo IDs 
  • Completely severed the account integration link connecting Lenovo profiles to Dropbox 
  • Mandated direct password verification, preventing any Lenovo ID sign-in without a primary Dropbox password 

Dropbox additionally noted in customer notices that internal access logs showed no conclusive evidence that stored user files were downloaded or viewed during the intrusions. 

Filed in Cellphones >Computers >Tablets. Read more about and .