Dropbox Breach: 5,000 Accounts Compromised via Lenovo ID Flaw

Dropbox Breach: 5,000 Accounts Compromised via Lenovo ID Flaw

First seen 2 Sep 2026, 15:44 UTC Technaduen.cryptonomist.chthecybersecguru.comwww.huntress.comwww.bloomberg.com+1 64.5

Article Content

Browse articles
ThreatCluster

Between August 4 and August 21, 2026, attackers exploited a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs and access approximately 5,000 Dropbox accounts without needing passwords. This incident affected users who had not enabled two-factor authentication (2FA). Dropbox's investigation revealed that the attackers could create Lenovo IDs using victims' email addresses, allowing them to log into corresponding Dropbox accounts. The breach was confirmed on September 2, 2026, with Dropbox taking immediate action to sever the connection between Lenovo IDs and Dropbox accounts, requiring passwords for future logins. Affected users reported unauthorized access and unexpected verification codes. This incident is linked to vulnerabilities similar to CVE-2026-55075 and CVE-2026-14781, highlighting risks in federated identity systems. Dropbox has communicated with affected users and implemented remediation measures.

Key Points: • 5,000 Dropbox accounts compromised due to a Lenovo ID verification flaw. • Attackers accessed accounts without passwords, exploiting weak email verification. • Dropbox has since removed Lenovo ID connections and requires passwords for access.

Timeline

2026-07-05
CVE-2026-14781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-07
CVE-2026-55075 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-04
Unauthorized access begins
Attackers exploit Lenovo's email verification flaw to register IDs and access Dropbox accounts.
thecybersecguru.com
2026-08-21
Unauthorized access ends
The window of unauthorized access to Dropbox accounts closes.
thecybersecguru.com
2026-09-02
Breach disclosed
Dropbox confirms the breach affecting 5,000 accounts and details the attack method.
thecybersecguru.com
2026-09-02
Remediation measures implemented
Dropbox severs Lenovo ID connections and requires passwords for future logins.
thecybersecguru.com