Dropbox has confirmed that approximately 5,000 user accounts were compromised in early August after attackers leveraged a flawed single sign-on (SSO) link with Lenovo IDs. The breach, which lasted from August 4 through August 21, allowed unauthorized actors to access accounts without ever needing the Dropbox password. This pathway stemmed from a “legacy integration” between Dropbox and Lenovo.
How the Authentication Bypass Worked
The attack exploited Lenovo’s email verification system. The flaw allowed anyone to register a Lenovo ID under someone else’s email address without verifying control of that inbox. Once the Gmail or Outlook-style address was tied to a Lenovo ID, Dropbox accepted it as legitimate identity when used via SSO. Because Dropbox matched based on email alone, the attacker gained access to the Dropbox account associated with that email—no password required.
None of the compromised accounts had two-factor authentication (2FA) enabled. Only in fewer than one third of the breached accounts did the attackers view or download stored content. For the majority, no content appeared to have been accessed.
Actions Taken & Current Protections
Once the issue was uncovered, Dropbox and Lenovo jointly severed the connection: all existing Lenovo ID-authenticated sessions were terminated, the link between Lenovo IDs and Dropbox accounts was removed, and Dropbox now requires users to enter their Dropbox password when authenticating via Lenovo. Affected users have been notified.
Lenovo characterized the problem as a legacy authentication integration that “could be used to improperly authenticate certain Dropbox accounts,” and stated that its own direct customers were not impacted by the misconfiguration.
What This Means for Users & Best Practices
This incident highlights how trust relationships between services can become vectors for account takeover without any visible signs like password leaks or phishing. Even more so when single sign-on mechanisms are involved, and when users haven’t enabled 2FA—something that would have blocked this attack entirely.
To guard against similar attacks, users should enable multi-factor authentication on all accounts, review current login and SSO options, revoke suspicious third-party identity connections, change passwords if in doubt, and monitor for unfamiliar account sessions. Enterprises should audit all legacy integrations, especially ones they may no longer actively manage.
This breach underscores an uncomfortable but growing front in cybersecurity: authentication flaws in federated identity systems. Even systems designed for convenience can compromise security if any link in the trust chain is weak. Watch for future disclosures and ensure your identity and access management practices include regular review of all third-party SSO and legacy login paths—before they become someone else’s punch-card into your data.