Dropbox Accounts Compromised via Lenovo ID Authentication Flaw

Dropbox Accounts Compromised via Lenovo ID Authentication Flaw

First seen 2 Sep 2026, 15:44 UTC TechnaduCybersecuritynewsen.cryptonomist.chthecybersecguru.comwww.huntress.com+6 66.0

Article Content

Browse articles
ThreatCluster

Between August 4 and August 21, 2026, approximately 5,000 Dropbox accounts were compromised due to a flaw in Lenovo's email verification process. Attackers exploited this vulnerability to register fraudulent Lenovo IDs using victims' email addresses, allowing them to access Dropbox accounts without needing passwords. The breach affected users who did not have two-factor authentication enabled. Dropbox has since terminated all sessions authenticated through Lenovo IDs and implemented new security measures requiring users to enter their Dropbox passwords for Lenovo ID logins. Notifications were sent to affected users starting August 31, 2026. The incident is linked to known vulnerabilities CVE-2026-55075 and CVE-2026-14781, highlighting risks in federated identity systems.

Key Points: • Approximately 5,000 Dropbox accounts were compromised due to a Lenovo ID flaw. • Attackers exploited weak email verification to register fraudulent Lenovo IDs. • Dropbox has implemented new security measures and notified affected users.

Ask AI about this cluster

Timeline

2026-07-05
CVE-2026-14781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-07
CVE-2026-55075 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-04
Unauthorized access begins
Attackers exploited Lenovo ID flaw to access Dropbox accounts using victims' email addresses.
thecybersecguru.com
2026-08-21
Unauthorized access ends
The window for unauthorized access to Dropbox accounts via Lenovo IDs closes.
thecybersecguru.com
2026-08-31
User notifications sent
Dropbox began notifying affected users about the unauthorized access to their accounts.
thecybersecguru.com
2026-09-02
Dropbox discloses breach
Dropbox publicly confirms the breach and outlines the security measures taken in response.
thecybersecguru.com