logo

Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw

ID: 84c9a560-95f0-544e-9192-db692cf33268

STIX ID: report--84c9a560-95f0-544e-9192-db692cf33268

Feed Name: cybersecurityNews.com

Threat Score
68/100

Date Published: 2026-09-02

Date Updated: 2026-09-16

Author: Guru Baran

...
...

Dropbox disclosed that about 5,000 user accounts were compromised in August 2026 after attackers abused a Lenovo ID sign-in integration: attackers registered Lenovo IDs using victims' email addresses (due to Lenovo's email verification flaw) and then accessed Dropbox accounts tied to those emails without needing Dropbox passwords. The incident was an account-takeover via federated authentication trust, primarily affecting accounts without Dropbox two-factor authentication; Dropbox terminated Lenovo-ID sessions, removed the association, and required passwords for Lenovo-ID logins while recommending password changes and enabling two-step verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.