Numerous Dropbox users recently received security notices stating that their accounts had been accessed without authorization between 4 and 21 August 2026. This was not a matter of Dropbox’s infrastructure being hacked. The actual cause, remarkably, was a trust flaw between Lenovo ID registration and Dropbox SSO login.
An Email Address Alone Could Seize a Dropbox Account
According to the disclosed attack chain, the Lenovo ID registration process contained an email-verification defect. An attacker could use a victim’s email to create a Lenovo account, without any email verification code being sent to confirm that the address truly belonged to the registrant.
The problem was then amplified by Dropbox’s SSO login mechanism. Dropbox matches an existing account based on the email identity supplied by Lenovo. Therefore, after logging in with a forged Lenovo ID, an attacker could gain complete control of the corresponding Dropbox account, without a password or any other verification. One affected developer, Yoni Levy, shared screenshots of the notification, noting he had never held a Lenovo account.

More seriously, victims did not even need to have previously registered a Lenovo ID or linked a Dropbox account. Dropbox and Lenovo have long maintained a cloud-storage partnership, allowing Lenovo users to purchase and use Dropbox through the relevant services. As discussion among security researchers noted, Dropbox itself never required verification of the existing account before honouring the new SSO connection, so the failure was not Lenovo’s alone.
Dropbox Has Revoked Sessions and Changed Its Login Flow
Following its investigation, Dropbox has revoked all sessions established through Lenovo ID and severed the link between affected accounts and Lenovo ID. Users who wish to continue accessing their account via Lenovo ID must now enter their Dropbox password to verify, and can no longer log in directly.
An audit found that some accounts were accessed by attackers within the attack window. Dropbox states that fewer than a third of the affected accounts had files viewed or downloaded. As of now, Lenovo has not disclosed the incident in a security advisory.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!