Dropbox Breach Exposes ~5,000 Accounts via Lenovo ID Flaw

Dropbox disclosed that about 5,000 accounts were accessed without authorization between August 4 and 21, with files in under a third viewed or downloaded. Attackers exploited a trust-chain flaw in the Lenovo ID integration by registering a Lenovo ID with victims' emails, requiring no Dropbox password or email access.

2026-09-02 ~ 2026-09-03 · 3 related posts