By Jason Nelson
3 min read
Multiple Dropbox users were notified that unauthorized parties accessed their accounts through an authentication flaw involving Lenovo ID.
The incident appears to have exploited the way Dropbox handled single sign-on, or SSO, through Lenovo IDs. Dropbox said an issue with Lenovo’s email verification process allowed unauthorized parties to register Lenovo IDs using other people’s email addresses and then use those identities to access the Dropbox accounts associated with the same addresses.
Myriad: Tesla highs in September? Click to make your prediction.
In a letter to affected users, Dropbox said accounts were accessed without authorization between August 4 and August 21, 2026, though the company said logs showed no evidence that files were viewed or downloaded.
“We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled,” a Dropbox spokesperson told Decrypt. “Our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using another person’s email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
“Approximately 5000 Dropbox accounts were impacted, and less than a third of these affected accounts had files viewed or downloaded,” the spokesperson added. “We’ve emailed all impacted users directly. Customers with questions about their account activity should contact our support team. If a user didn’t receive an email from us, their account was not impacted.”
Developer Yoni Levy, one of the affected users, posted screenshots of the letter on X.
One screenshot shows Dropbox warning Levy that a new web browser had signed into his account from “Near Canary Wharf, England, United Kingdom” on August 18 at 6:06 a.m. local time. The login used Chrome on Windows.
Levy said he had never had a Lenovo account and had not been to the United Kingdom.
A subsequent notification from Dropbox told Levy that its investigation found an unauthorized party had registered a Lenovo ID using his email address and then used that ID to log into his Dropbox account.
The attack did not appear to require a victim’s Dropbox password or access to their email inbox. According to Dropbox, affected accounts were linked to Lenovo IDs and did not have Dropbox two-factor authentication enabled, allowing attackers to use newly registered Lenovo IDs with matching email addresses to access existing accounts without additional verification.
The warning follows other account-security scares affecting major online platforms.
On Tuesday, X users reported a surge of unsolicited password-reset emails, unfamiliar login alerts and account lockouts, though X said it had found no evidence of a new breach. An X engineer said attackers appeared to be attempting to take control of accounts to gain access to X Money.
Decrypt-a-cookie
This website or its third-party tools use cookies. Cookie policy By clicking the accept button, you agree to the use of cookies.