Attackers exploited a flaw in Lenovo ID's email-verification process to create Lenovo identities using victims' email addresses without controlling their inboxes. Because Dropbox accepted Lenovo as a federated identity provider and matched its asserted email claims to existing Dropbox accounts, the attackers could obtain passwordless access to accounts, including accounts whose owners had not created or linked a Lenovo ID. The reported abuse occurred between August 4 and August 21, 2026.
Dropbox invalidated all Lenovo-authenticated sessions, removed Lenovo ID associations from affected accounts, and now requires users to enter their Dropbox password before enabling Lenovo authentication. Dropbox said its logs found no evidence that files were viewed or downloaded, though the unauthorized access could have exposed sensitive data; the number of affected accounts and broader scope of the issue were not disclosed.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Between August 4 and August 21, attackers allegedly registered Lenovo IDs using email addresses they did not control and used Dropbox's federated Lenovo login flow to access Dropbox accounts with matching email addresses. The reported attack did not require victims' Dropbox passwords or prior Lenovo-Dropbox account links.
Around August 31, Dropbox began sending breach-notification emails stating that unauthorized access had occurred between August 4 and August 21. Dropbox said its logs showed no evidence that attackers viewed or downloaded files, although notifications warned that files may have been accessed.
Dropbox stated that it reported the Lenovo-ID single sign-on breach to relevant data-protection regulators, in addition to emailing known affected users and offering support.
Lenovo stated that its customers were unaffected by the abuse of the legacy Lenovo-ID Dropbox login integration and said it was continuing to investigate the issue.
Dropbox published revised service terms that limit liability involving third-party products and customers' non-use of available mitigations, and expanded customer liability provisions. It also revised its privacy policy to explicitly permit analysis of stored files to improve services, with the FAQ referring to AI training.
Dropbox ended the reported abuse by expiring Lenovo ID-authenticated sessions and removing Lenovo-Dropbox associations on affected accounts. It also changed the flow to require entry of the Dropbox password before Lenovo ID authentication can be enabled for an existing account.
Dropbox stated that approximately 5,000 Lenovo ID-linked accounts without Dropbox two-factor authentication were affected. It later said files were viewed or downloaded in fewer than one-third of affected accounts, revising its earlier statement that logs showed no such activity.
Casa co-founder Jameson Lopp said he was among the Dropbox users affected by the Lenovo ID login abuse. He said the attackers attempted to open only a file named IMPORTANT.rtf, which he had encrypted locally before uploading.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
15 references tracked. Mallory keeps watching after this page renders.
bitdefender.com
Open sourcecysecurity.news
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourceheise.de
Open sourcedecrypt.co
Open sourcethecybersecguru.com
Open sourcenews.ycombinator.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.