Dropbox breach hits ~5,000 accounts via trusted Lenovo ID verification flaw

jedisct1 · x · 2026-09-03

Dropbox disclosed that roughly 5,000 accounts were accessed without authorization between August 4 and 21, with files viewed or downloaded in fewer than a third of them.

The attack vector was strikingly simple: registering a Lenovo ID with someone else's email address was enough — Dropbox trusted Lenovo's verification and handed over a session. Dropbox has terminated every Lenovo ID session and notified regulators.

Related event: Dropbox Says 5,000 Accounts Breached via Lenovo ID Trust Chain Flaw(2 posts)→

Original post →

More from Safety

Safety channel →