Dropbox says 5,000 accounts were breached through Lenovo ID integration
Key Takeaways
- •Attackers used a Lenovo ID integration to enter Dropbox accounts without a password by matching victim email addresses to newly created Lenovo IDs.
- •About 5,000 Dropbox accounts were accessed during the attack window, and fewer than one-third showed evidence of files being viewed or downloaded.
- •Dropbox said none of the affected accounts had multi-factor authentication enabled.
- •Dropbox terminated Lenovo-authenticated sessions, disabled the integration, and now requires a Dropbox password for account access.
- •Lenovo said the issue came from a legacy integration and stated that its own users were not affected.

Cloud storage service Dropbox informed about 5,000 users this week that their accounts were accessed by hackers between August 4 and August 21, 2026, because a dormant Lenovo ID sign-in integration allowed direct access without a password.
The users at risk were Dropbox customers who stored files in the cloud storage app and had not enabled multi-factor authentication, underscoring how account protections can matter even when a service’s core platform is not directly breached.
Dropbox login accessed without a password
The loophole that gave the attackers access was the integration between Lenovo ID and Dropbox, rather than either product itself. According to TheNextWeb, anyone could register a Lenovo ID using an email address that did not belong to them because Lenovo’s setup did not verify that the address belonged to the registrant. Dropbox, however, treated the Lenovo token as proof of identity and then allowed access to the matching account.
The security writer The CyberSec Guru, cited by 9to5Mac, described the sequence of events. Attackers collected public email addresses and then enrolled a Lenovo ID under a victim’s address. They then used the “Continue with Lenovo” option on Dropbox, which gave them access to a live session without a password prompt and, from there, direct access to the Dropbox account.
One user who recovered a previously accessed rogue account found it displayed the name “John Madden,” which 9to5Mac said is a sign of bulk registrations.
What was taken in the attack?
Files were viewed or downloaded on less than a third of the roughly 5,000 accounts opened during the attack period. That implies about 1,500 accounts had material taken, according to 9to5Mac’s update, while around 3,500 showed no traces of files being touched. It remains unclear whether the intruders were looking for specific documents or simply moving through accounts automatically.
Spokesperson Tim Rathschmidt said none of the breached accounts used multi-factor authentication. Rathschmidt also said Dropbox does not expect the incident to affect its business.
Dropbox shuts off Lenovo ID integration
After learning of the issue, Dropbox terminated every session authenticated through a Lenovo ID, disabled the integration, and now requires a native Dropbox password before any account can be accessed.
Lenovo traced the incident to a “legacy integration” that it said could be used to “improperly authenticate certain Dropbox accounts.” The company said its own users were completely unaffected and confirmed that its investigation was still ongoing.
The breach was uncovered through a later investigation and was not detected by the monitoring systems of either company, highlighting the risk posed by older single-sign-on links that remain active after user behavior and security expectations have changed.
Multi-factor authentication would have blocked the attack because the loophole relied on access without a password through the Lenovo ID integration, leaving no second verification step in place.