Particle.news

Dropbox Accounts Compromised Through Faulty Lenovo‑ID

The incident shows how a legacy third‑party login can bypass protections, raising the prospect of regulatory scrutiny.

Overview

  • Attackers created Lenovo‑ID accounts tied to other people’s email addresses and used those IDs to sign into Dropbox accounts between August 4 and August 21, 2026.
  • The weakness was a Lenovo email‑verification error that let attackers register Lenovo‑IDs for addresses they did not control and rely on Dropbox treating those log‑ins as trusted when two‑factor authentication was not enabled.
  • About 5,000 Dropbox accounts without 2FA were accessed and files were downloaded from fewer than one‑third of those accounts, with Dropbox notifying each affected user whether their files were viewed or taken.
  • Dropbox ended all Lenovo‑ID sessions, removed the Lenovo linkages, now requires a Dropbox password before Lenovo sign‑ins, reported the incident to data‑protection authorities, and published planned terms and privacy changes that shift liability and broaden data‑use language.
  • The disclosure knocked Dropbox shares lower and highlights that users who skip 2FA or rely on legacy third‑party sign‑ins face higher risk, so enabling two‑factor authentication or passkeys is the primary defense.