Tech News

Dropbox Accounts Compromised via Lenovo ID Login Flaw Affecting 5,000 Users

A Dropbox account opened by a stranger, with no password, no phishing, and without you ever having created a Lenovo account. That is what happened to around 5,000 users between August 4 and August 21, 2026. Here is what we know.

Since August 31, 2026, Dropbox has started notifying some users by email to inform them of unauthorized access to their accounts. This message was also widely shared, notably on the social network X by developer Yoni Levy. It states that these intrusions occurred between August 4 and August 21, 2026.

This security incident is linked to Lenovo ID: but what does Lenovo have to do with a Dropbox incident? In fact, Dropbox offers several sign-in methods in addition to the classic username-and-password pair. Among them is a single sign-on (SSO) option via Lenovo ID, which allows users to sign in with a Lenovo user account. In other words, Dropbox relies on Lenovo as an identity provider: if Lenovo says an email address is verified, Dropbox treats it as such.

That is where everything went wrong...

A Lenovo ID Created with Your Email Address, and You're In

According to the email sent to victims, a flaw in Lenovo's email verification process allowed an attacker to create a Lenovo ID using anyone's email address, without ever proving access to the corresponding mailbox. Then, all it took was clicking the Lenovo sign-in button on Dropbox's authentication page. Lenovo passed the email address to Dropbox, which matched it to an existing account and opened a session.

"Although you may not have a Lenovo ID, our investigation determined that an issue in Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID with your email address, and then use that Lenovo ID to sign in to the Dropbox account associated with that address," the email says.

What you need to understand:

  • The attacker does not need to know the victim's password, or even be able to access the email address.
  • The attacker only needs to know the email address used by the targeted person for their Dropbox account.

Lenovo and Dropbox: two major companies. I have to wonder: how could this be missed? This should have been part of the test scenarios when implementing this authentication method. The only effective protection against this vulnerability: two-factor authentication on the Dropbox side (yet another good reason to enable it wherever possible).

Still, the attackers had time to have some fun: around 5,000 Dropbox accounts are affected. They were able to view or download files from the Dropbox account in fewer than a third of the cases, which still represents about 1,600 people. In principle, depending on your case (whether files were viewed or not), the email sent by Dropbox is not the same: Dropbox therefore knows exactly how each account was impacted.

Who Is to Blame?

Dropbox points the finger at Lenovo in its email. But who is actually at fault? Responsibility is shared, and I would even say this is more Dropbox's fault. Linking a new sign-in method to an existing account based solely on an email address, without requiring the account password first, is a real problem. Dropbox should have put the necessary verification mechanisms in place to prevent that from being possible. And above all, this scenario should have been tested: there is nothing exotic about it.

Following this incident, Dropbox took the following actions:

  • Sessions expired. All sessions opened via a Lenovo ID were revoked.
  • Links removed. The association between Lenovo ID and Dropbox account was removed for the affected accounts.
  • Password required. From now on, no Lenovo ID can be associated with a Dropbox account without first entering the Dropbox password. Too bad they are only doing this now.

If you did not receive an email from Dropbox, your account is not affected. 5,000 accounts is a small number at Dropbox's scale, but it is already too many.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.