logo

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

ID: d2ff2fe6-7ab4-5156-b907-a0bddfe70874

STIX ID: report--d2ff2fe6-7ab4-5156-b907-a0bddfe70874

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-09-02

Date Updated: 2026-09-05

...
...

Dropbox warned about a compromise affecting roughly 5,000 user accounts after attackers exploited a legacy Lenovo login integration and an issue in Lenovo’s email verification process to register Lenovo IDs tied to victims’ email addresses and access their Dropbox accounts without requiring Dropbox passwords. The breach ran from August 4–21, fewer than a third of the affected accounts had files accessed, none of the compromised accounts had two-factor authentication enabled, and Dropbox responded by severing the Lenovo link, expiring sessions, and instructing users to change passwords and enable 2FA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.