logo

Dropbox accounts breached through Lenovo email verification flaw

ID: 85c037f6-3ba5-579e-8c29-97c34b5bf7cd

STIX ID: report--85c037f6-3ba5-579e-8c29-97c34b5bf7cd

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-09-02

Date Updated: 2026-09-10

Author: Bill Toulas

...
...

Dropbox disclosed that attackers abused a flaw in Lenovo's email verification to register fake Lenovo IDs and log into linked Dropbox accounts without passwords between August 4–21, affecting about 5,000 accounts; Dropbox and Lenovo mitigated the issue by expiring Lenovo-authenticated sessions and requiring Dropbox passwords for Lenovo ID logins while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.