Dropbox breach hits ~5,000 accounts via trusted Lenovo ID verification flaw
jedisct1 · x · 2026-09-03
Dropbox disclosed that roughly 5,000 accounts were accessed without authorization between August 4 and 21, with files viewed or downloaded in fewer than a third of them.
The attack vector was strikingly simple: registering a Lenovo ID with someone else's email address was enough — Dropbox trusted Lenovo's verification and handed over a session. Dropbox has terminated every Lenovo ID session and notified regulators.
Related event: Dropbox Says 5,000 Accounts Breached via Lenovo ID Trust Chain Flaw(2 posts)→
More from Safety
- Survey: 87% of National Security Pros Say AI Could Escape Control in 10 Years — vkrakovna · 2026-09-03
- Trump Administration Backs OpenAI in New York Times Copyright Case Over Chatbot Training — nordicinst · 2026-09-03
- Toby Ord: AI safety incentives often locally point to capabilities, not safety — tobyordoxford · 2026-09-03
- Report: Most Washington Officials Unfamiliar With AI, No Strategy for Agents — Afinetheorem · 2026-09-03
- X to ship instant auto-revert and auto-logout when hackers change your email, password or phone — Scobleizer · 2026-09-03
- Palisade Research documents shutdown resistance in reasoning models — 233C · 2026-09-03