Attacker Accessed Dropbox Accounts Through a Lenovo ID Issue
Dropbox warned some users about unauthorized access to their accounts. The attacker reportedly exploited email verification in Lenovo ID to sign in without knowing the Dropbox password.

Lenovo ID integration with Dropbox became a path to unauthorized access to some Dropbox accounts. According to notifications sent by the service to affected users, the attacker exploited an issue with Lenovo ID email verification. The access reportedly took place from August 4 to 21, 2026, while the notifications were sent to users on September 1 and 2.
The mechanism reportedly allowed the attacker to register a Lenovo ID using the victim’s email address and then use that identity to sign in to the corresponding Dropbox account. The affected accounts could therefore be accessed without knowing their Dropbox passwords.
Lenovo ID integration and the method of exploitation
According to the content of Dropbox’s customer notifications, the issue involved linking an external Lenovo ID account to an existing Dropbox account, with the email address playing a key role.
In a statement to BleepingComputer, Lenovo described the issue as involving an older Lenovo ID and Dropbox integration. The company also said it had mitigated the risk together with Dropbox. However, a complete technical description of the email verification flaw and the precise division of responsibility between the companies have not been publicly disclosed.
According to the available notifications, Dropbox invalidated sessions verified through Lenovo ID. It also added a requirement to enter the Dropbox password for this sign-in method. This change is intended to prevent the external identity alone, with the same email address, from being sufficient to access an existing account.
Unknown scope and file activity
The number of affected accounts has not been publicly confirmed. In the cited notifications, Dropbox told users that its logs showed no evidence that the attacker viewed or downloaded files. However, this is not independent confirmation of what happened in every individual case.
It is likewise not publicly documented whether the attacker modified files or worked with their metadata in some accounts. No primary security notice from Dropbox or Lenovo has been published about the incident so far; the available confirmations come from customer notifications and Lenovo’s statement to the media.
Why the case matters
Dropbox is used to store personal and corporate data, making the security of login links with external identities important. This case highlights the risk of federated login when a service links an external identity to an existing account based only on an email address.
For users who received a notification, it is relevant that Dropbox invalidated the affected sessions and changed the sign-in flow through Lenovo ID. The publicly available information does not yet indicate whether the Lenovo ID connection with Dropbox will be permanently discontinued or whether the companies will announce further measures.
Further information could come from a public security notice from both companies, confirmation of the number of affected accounts, and possible clarification of the extent of access to the data.
Sources
- BleepingComputer – Cites Dropbox’s notification to affected users, gives the access interval, describes the mitigations taken, and includes Lenovo’s statement about an older integration.
- 9to5Mac – Independently reproduces the content of Dropbox’s customer notification, including the description of the Lenovo ID exploitation and the claim that there was no evidence of files being downloaded or viewed.
Verified and updated: 09/02/2026 17:09



