Dropbox Hit by Federation Bug: 5,000 Accounts Taken via Lenovo ID

Dropbox has revealed that roughly 5,000 user accounts were breached in August 2026 through a vulnerability involving its Lenovo ID sign-in link. The issue wasn’t due to stolen passwords—but a federated identity trust flaw tied to how email verification was handled, allowing attackers to exploit Lenovo ID to access Dropbox accounts without the users’ passwords.

How It Happened

The breach took place between August 4 and August 21, when individuals were able to register Lenovo IDs using email addresses already associated with existing Dropbox accounts. Because email address matching was treated as sufficient proof of ownership, the attackers bypassed the need for a Dropbox password and gained full access.

No two-factor authentication (2FA) was enabled on the affected Dropbox accounts, which magnified the risk. The flaw surfaced due to Dropbox’s “legacy integration” with Lenovo’s ID system—specifically, Lenovo’s email-verification process failed to verify that the registering party actually controlled the mailbox.

Scope and Impact

According to official notices, attackers were able to view and download content from some compromised accounts, though Dropbox states multiple cases showed no evidence of file access. The affected users didn’t all knowingly set up Lenovo IDs or connect them to Dropbox, meaning simply sharing an email address was enough to be exposed.

Dropbox’s Fixes & User Advice

In response, Dropbox has revoked all sessions that used Lenovo ID for authentication, removed Lenovo ID associations, and altered its login workflow. Now, even when signing in via Lenovo ID, users must supply their Dropbox password.

For those affected, suggested steps include changing Dropbox and email passwords, enabling two-step verification, checking recent activity like file access and shared links, and reviewing recovery settings.

What Organizations Should Learn

This incident highlights risks that come when integrating with external identity providers without robust verification. Best practices include verifying email ownership before linking identities, avoiding automatic account matching just based on email, boosting authentication security with phishing-resistant multi-factor authentication, and monitoring for unusual federated sign-ins.

Why This Matters:Federated or single sign-on (SSO) systems are meant to streamline access—but when leaks and flawed trust relationships creep in, they can expose large volumes of data without the usual authentication barriers. The Dropbox–Lenovo breach underlines that even when passwords aren’t stolen, identity systems still need to enforce strict email ownership checks and enforce 2FA.

Close observation ahead:Keep an eye on how both Dropbox and Lenovo update their policies and integrations. Users should demand transparency around what “legacy” means, audit which identity services are linked to their accounts, and ensure that any third-party login options carry the same security heft as primary ones.