Unauthorised access to Dropbox accounts via a Lenovo ID integration
Between 4 and 21 August 2026, unauthorised access to Dropbox accounts occurred via the authentication mechanism associated with Lenovo ID. Dropbox subsequently identified that the affected accounts were linked to Lenovo ID and did not have two-factor authentication enabled. According to information provided by Dropbox, approximately 5,000 accounts were affected during this period. The incident did not involve the theft of Dropbox passwords, but rather the misuse of a federated authentication mechanism between Dropbox and Lenovo.
According to the investigation reported by Dropbox, a flaw in Lenovo ID’s email verification process allowed third parties to register a Lenovo account using another person’s email address and subsequently use that identity to access the Dropbox account associated with the same address. Dropbox stated that fewer than a third of the approximately 5,000 affected accounts showed any activity involving the viewing or downloading of files. Lenovo, for its part, described the issue as a legacy integration between Lenovo ID and Dropbox that could be exploited to improperly authenticate certain accounts. After identifying the issue, Dropbox terminated all sessions authenticated via Lenovo ID, removed the links between Lenovo and Dropbox accounts, and modified the process to require the Dropbox password before allowing access via Lenovo ID. Dropbox also notified affected users and data protection regulators of the incident.
Dropbox now considers the access mechanism used during the incident to have been mitigated: sessions authenticated via Lenovo ID have been terminated, existing links have been removed, and an additional verification step using the Dropbox password has been introduced. The company informed affected users directly of the situation and stated that those who had not received such a notification were not among the affected accounts. Lenovo has indicated that its own customers were not affected and that its investigation is ongoing. Therefore, according to the latest statements available from the companies, access via the mechanism used in the incident has been blocked, whilst Lenovo’s investigation into the affected integration remains open.
Translated with DeepL.com (free version)


