Technadu
Dropbox Breach: 5,000 Accounts Compromised via Lenovo ID Flaw
Article Content
Between August 4 and August 21, 2026, attackers exploited a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs and access approximately 5,000 Dropbox accounts without needing passwords. This incident affected users who had not enabled two-factor authentication (2FA). Dropbox's investigation revealed that the attackers could create Lenovo IDs using victims' email addresses, allowing them to log into corresponding Dropbox accounts. The breach was confirmed on September 2, 2026, with Dropbox taking immediate action to sever the connection between Lenovo IDs and Dropbox accounts, requiring passwords for future logins. Affected users reported unauthorized access and unexpected verification codes. This incident is linked to vulnerabilities similar to CVE-2026-55075 and CVE-2026-14781, highlighting risks in federated identity systems. Dropbox has communicated with affected users and implemented remediation measures.
Key Points: • 5,000 Dropbox accounts compromised due to a Lenovo ID verification flaw. • Attackers accessed accounts without passwords, exploiting weak email verification. • Dropbox has since removed Lenovo ID connections and requires passwords for access.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.