Technology
Dropbox breach linked to authentication flaws with Lenovo single sign-on
A combination of a Lenovo verification loophole and Dropbox's implicit account-linking process enabled unauthorized access to some user accounts.
The short version
- Dropbox notified multiple users of unauthorized access to their accounts that occurred between August 4 and August 21, 2026.
- The breach resulted from a combination of a flaw in Lenovo's email verification process and Dropbox's failure to prompt users for authentication before linking the new single sign-on (SSO) identity.
- Dropbox stated that it has resolved the vulnerability and terminated all active sessions previously authenticated using a Lenovo ID.
Key facts
- Dropbox sent email notifications to multiple users advising them of unauthorized access to their accounts between August 4 and August 21, 2026.[9to5Mac]
- A flaw in Lenovo's email verification process allowed unauthorized parties to register a Lenovo ID using a victim's email address without requiring access to their email inbox.[9to5Mac]
- When attackers used the registered Lenovo IDs to log in, Dropbox implicitly linked the identity to existing accounts based on the email address without requesting password confirmation or consent.[9to5Mac]
- Dropbox reported that its system logs show no evidence that user files were viewed or downloaded during the security incident.[9to5Mac]
- Dropbox stated that the flaw has been corrected and all existing sessions authenticated via a Lenovo ID have been expired.[9to5Mac]