Technadu
Dropbox Accounts Compromised via Lenovo ID Authentication Flaw
Article Content
Between August 4 and August 21, 2026, approximately 5,000 Dropbox accounts were compromised due to a flaw in Lenovo's email verification process. Attackers exploited this vulnerability to register fraudulent Lenovo IDs using victims' email addresses, allowing them to access Dropbox accounts without needing passwords. The breach affected users who did not have two-factor authentication enabled. Dropbox has since terminated all sessions authenticated through Lenovo IDs and implemented new security measures requiring users to enter their Dropbox passwords for Lenovo ID logins. Notifications were sent to affected users starting August 31, 2026. The incident is linked to known vulnerabilities CVE-2026-55075 and CVE-2026-14781, highlighting risks in federated identity systems.
Key Points: • Approximately 5,000 Dropbox accounts were compromised due to a Lenovo ID flaw. • Attackers exploited weak email verification to register fraudulent Lenovo IDs. • Dropbox has implemented new security measures and notified affected users.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.