Incident
Published 2026-09-01
Verified 2026-09-19

Dropbox: Lenovo ID federation let attackers into about 5,000 accounts

Decrypt published on 1 September 2026 that Dropbox had emailed users about unauthorised access between 4 and 21 August 2026 via Lenovo ID single sign-on. A Dropbox spokesperson told Decrypt the company identified unauthorised access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled, and that an issue with Lenovo email verification allowed an unauthorised party to register a Lenovo ID using another person's email address and then use that Lenovo ID to log into the Dropbox account associated with that address. The spokesperson said approximately 5,000 Dropbox accounts were impacted, less than a third of those had files viewed or downloaded, and Dropbox had emailed all impacted users; users who did not receive an email were not impacted. Decrypt also reported that Dropbox's notification letter said logs showed no evidence files were viewed or downloaded, and that Dropbox has since changed how Lenovo IDs can access accounts. Affected user Yoni Levy posted screenshots of a new-browser sign-in alert from near Canary Wharf (Chrome on Windows, 18 August) and said he had never had a Lenovo account. This desk has not found a Dropbox public advisory page; the company notice in hand is the user email plus the spokesperson comments to Decrypt.

Product
Dropbox (Lenovo ID sign-in)
Exploited in Australia?
unknown
Patch to
Dropbox: expire Lenovo ID sessions and require the Dropbox password before a Lenovo ID can authenticate; enable Dropbox 2FA; users without a notification email were not in the notified set

Primary: Decrypt (1 Sep 2026; Dropbox spokesperson) ยท 9to5Mac (1 Sep 2026; quotes Dropbox email)

breaches identity cloud