Dropbox has confirmed that attackers accessed thousands of user accounts after exploiting an email verification weakness in a legacy authentication integration with Lenovo.
The issue allowed an unauthorized party to register a Lenovo ID using the email address associated with an existing Dropbox account. Dropbox then accepted the Lenovo identity as sufficient authentication, allowing the attacker to access the corresponding Dropbox account without knowing its password.
Dropbox told affected users that unauthorized access occurred between Aug. 4 and Aug. 21, 2026. Approximately 5,000 accounts were compromised, according to information provided by Dropbox, with files reportedly viewed or downloaded from some affected accounts.
Not every compromised account appears to have suffered file access. In a notification reviewed by BreachNews, Dropbox told one affected user that its logs showed no evidence that files in that account were viewed or downloaded.
Lenovo verification issue bypassed Dropbox passwords
The attack stemmed from an authentication relationship between Dropbox and Lenovo that allowed users with verified Lenovo IDs to access Dropbox accounts associated with the same email address.
According to Dropbox’s notification, an issue in Lenovo’s email verification process allowed an unauthorized party to create a Lenovo ID using another person’s email address.
Once the fraudulent Lenovo ID had been created, the attacker could use it to authenticate to the Dropbox account registered with that email address.
The weakness effectively shifted trust from Dropbox’s own authentication process to Lenovo’s verification of the user’s email address. If Lenovo incorrectly verified ownership of an email address, Dropbox could accept the resulting identity even though the attacker did not possess the victim’s Dropbox password.
The technique represents an authentication bypass through a trusted third-party identity provider rather than a compromise of Dropbox account passwords.
Legacy Lenovo integration blamed for unauthorized access
Lenovo described the issue as involving a legacy integration between Lenovo ID and Dropbox that could be abused to improperly authenticate certain Dropbox accounts.
The company said Lenovo and Dropbox worked together to mitigate the issue after it was identified. Lenovo said its own customers were not affected by the vulnerability.
The incident highlights a risk inherent in federated authentication systems: a security weakness at one identity provider can potentially undermine authentication at another service that trusts its identity assertions.
Dropbox supports several forms of federated authentication and single sign-on. In this case, the affected integration allowed Lenovo identities to serve as a trusted route into Dropbox accounts.
Dropbox terminates Lenovo-authenticated sessions
Dropbox responded by expiring all active sessions authenticated through Lenovo IDs and severing existing links between Lenovo identities and affected Dropbox accounts.
The company also changed the authentication flow so that a Lenovo ID can no longer provide direct access to a Dropbox account without the user first entering the corresponding Dropbox password.
Dropbox recommended that affected users change both their Dropbox and email account passwords and enable two-step verification.
The company’s security documentation says Dropbox can require additional verification when users attempt to access an account from an unfamiliar device or location.
Some accounts had files accessed
The scope of file exposure appears to vary between affected users.
The breach notification reviewed by BreachNews states that Dropbox detected unauthorized account access but found no evidence that files belonging to that particular recipient were viewed or downloaded.
However, Dropbox has reportedly determined that attackers viewed or downloaded content from some of the approximately 5,000 compromised accounts.
Dropbox has not publicly disclosed how many accounts experienced file access, what types of files were obtained, or whether the attacker specifically targeted particular users.
The attack window lasted from Aug. 4 through Aug. 21 before the vulnerable authentication path was shut down.
The incident demonstrates how identity federation can create an authentication dependency between otherwise separate services. Even users who had never intentionally created a Lenovo ID could reportedly be affected because an attacker could register one using their email address and then leverage Dropbox’s trust in that identity.










