Dropbox Says 5,000 Accounts Hit by Lenovo ID Authentication Flaw
Key Takeaways
- •Attackers exploited a flaw in Lenovo's email verification process to register Lenovo IDs with other people's email addresses and access their linked Dropbox accounts between August 4 and August 21, 2026.
- •Approximately 5,000 Dropbox accounts were impacted, and fewer than a third of those had files viewed or downloaded, according to Dropbox.
- •The attack did not require victims' Dropbox passwords or email inbox access, and only accounts linked to Lenovo IDs without Dropbox two-factor authentication were affected.
- •Dropbox has since changed how Lenovo IDs can access accounts and has emailed all impacted users directly.
- •Developer Yoni Levy reported receiving a login alert from near Canary Wharf, England, despite never having a Lenovo account or visiting the United Kingdom.

Dropbox has notified users of unauthorized account access occurring between August 4 and August 21, 2026, after attackers exploited a flaw in how the cloud storage provider handled single sign-on (SSO) through Lenovo IDs.
The company said an issue with Lenovo's email verification process allowed unauthorized parties to register Lenovo IDs using other people's email addresses and then use those identities to log into the Dropbox accounts associated with the same addresses. In a letter to affected users, Dropbox said that while accounts were accessed without authorization, its logs showed no evidence that files were viewed or downloaded.
"We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled," a Dropbox spokesperson told Decrypt. "Our investigation determined that an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using another person's email address and then use that Lenovo ID to log into the Dropbox account associated with that email address."
"Approximately 5000 Dropbox accounts were impacted, and less than a third of these affected accounts had files viewed or downloaded," the spokesperson added. "We've emailed all impacted users directly. Customers with questions about their account activity should contact our support team. If a user didn't receive an email from us, their account was not impacted."
According to Dropbox, the attack did not appear to require a victim's Dropbox password or access to their email inbox. Affected accounts were linked to Lenovo IDs and did not have Dropbox two-factor authentication enabled, which allowed attackers to use newly registered Lenovo IDs with matching email addresses to access existing accounts without additional verification. Dropbox has since changed how Lenovo IDs can access accounts.
The incident highlights a broader risk with federated sign-on arrangements, in which one provider's identity credentials grant access to accounts on another service: when the upstream identity provider fails to properly verify email ownership, every downstream service that trusts those identities can be exposed, even when the downstream service itself was not breached. It also underscores why Dropbox's own two-factor authentication served as the effective last line of defense here — accounts with it enabled were not affected.
One affected user, developer Yoni Levy, posted screenshots of the letter on X:
so dropbox got hacked (never had a Lenovo account, haven't been to UK) pic.twitter.com/UoYRaJFuEC
— yoni | parser.eth (@yonilevy) August 31, 2026
One screenshot showed Dropbox warning Levy that a new web browser had signed into his account from "Near Canary Wharf, England, United Kingdom" on August 18 at 6:06 a.m. local time. The login used Chrome on Windows. Levy said he had never had a Lenovo account and had never been to the United Kingdom.
A subsequent notification from Dropbox informed Levy that its investigation found an unauthorized party had registered a Lenovo ID using his email address and then used that ID to log into his Dropbox account.
The warning follows other account-security scares affecting major online platforms. On Tuesday, X users reported a surge of unsolicited password-reset emails, unfamiliar login alerts, and account lockouts, though X said it had found no evidence of a new breach. An X engineer said attackers appeared to be attempting to take control of accounts in order to gain access to X Money.