Dropbox Trusted the Wrong Email. About 5,000 Accounts Were Opened.
Dropbox did not need to lose a password database for attackers to enter roughly 5,000 accounts. A legacy Lenovo sign-in path trusted email identities that had not been properly verified.
Attackers registered fraudulent Lenovo IDs using email addresses they did not control, then used those identities to access the Dropbox accounts associated with the same addresses. The affected accounts did not have Dropbox two-factor authentication enabled.
Seventeen days of unauthorised access
Dropbox identified access between 4 and 21 August 2026. Files were viewed or downloaded in fewer than one-third of the compromised accounts. That distinction matters: approximately 5,000 accounts were accessed, while the smaller figure describes accounts where Dropbox observed interaction with stored content.
The reported mechanism did not require the attacker to know the victim’s Dropbox password. Some notified users said they had never created a Lenovo ID, which is consistent with an attacker being able to register the external identity under somebody else’s email address.
The failure crossed two identity systems
Lenovo described the issue as a legacy integration between Lenovo ID and Dropbox that could improperly authenticate certain Dropbox accounts. The first failure was weak email ownership verification at the identity provider. The second trust decision happened when Dropbox accepted that external identity for the account carrying the same email address.
This was not reported as a compromise of Dropbox’s core password infrastructure. It was a federated identity failure: one service made an insufficiently verified claim, and another service treated that claim as sufficient proof of account ownership.
Dropbox closed the inherited login path
Dropbox expired every session authenticated through Lenovo ID, removed the links between Lenovo identities and Dropbox accounts, and changed the flow so that a Dropbox password must be entered before Lenovo can be used to access an account.
The company also reported the incident to data-protection regulators. Lenovo said its own customers were not affected and that its investigation was continuing. The available reporting does not identify the attacker or provide a public forensic report describing exactly which files were accessed.
Why MFA mattered without fixing the root cause
Dropbox said the affected accounts lacked its two-factor authentication. A second factor could have interrupted this specific login route, but MFA is not a substitute for verifying the identity being linked. An organisation should not allow a new external provider to become an account credential merely because both records contain the same email string.
Cloud storage raises the impact because one account can contain contracts, customer files, recovery documents, shared folders and links to material owned by other people. Even limited access can create downstream fraud, privacy and disclosure obligations.
What organisations and users should check
- Review Dropbox security notifications and account activity covering 4 through 21 August 2026.
- Remove unfamiliar sessions, devices, connected applications and identity-provider links.
- Enable phishing-resistant MFA and change the Dropbox password if unexpected activity appears.
- Inspect file events, downloads, shared-link changes and newly connected applications.
- Audit every federated sign-in integration for verified email ownership, explicit account-linking consent and step-up authentication.
- Require users to reauthenticate with an existing trusted credential before adding a new external identity provider.
The bigger lesson
Federation reduces password sprawl, but it also transfers trust. If an upstream provider lets an attacker claim another person’s email address and the downstream service binds that claim automatically, the weakest verification step becomes the effective security policy for both platforms.
Sources: Reuters reporting with Dropbox and Lenovo statements, BleepingComputer’s incident report, and Dropbox’s two-step verification guidance.


