Dropbox is warning users that an unauthorized party accessed accounts by exploiting a flaw in Lenovo's email verification process. Attackers used the flaw to register fraudulent Lenovo IDs, which were then leveraged to gain unauthorized access to Dropbox accounts. The vulnerability resided in Lenovo's identity and authentication pipeline, enabling account takeover without the victim's credentials. This incident highlights risks associated with third-party identity provider integrations and cross-platform authentication dependencies. Affected Dropbox users are being notified of the breach. The attack vector involves abusing the trust relationship between Dropbox and Lenovo's verification system. No specific CVE has been mentioned in the article content provided.
An unauthorized party exploited a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs using victims' email addresses. Dropbox uses Lenovo Identity Provider Services (IdP) as part of its authentication infrastructure, allowing users to log into Dropbox accounts using verified Lenovo IDs. The flaw allowed attackers to register a Lenovo ID with any email address without actually controlling that email address. Dropbox's identity-linking process trusted Lenovo's assertion that the attacker controlled the email address without requiring confirmation through the existing Dropbox login method. The attacker then used the fraudulent Lenovo ID to access the corresponding Dropbox account without needing the account's password. The vulnerability was related to a legacy integration between Lenovo ID and Dropbox. Unauthorized access occurred between August 4 and August 21, 2026. Approximately 5,000 Dropbox accounts were accessed, and the attacker viewed and downloaded content from some users. Notably, some victims did not even have Lenovo accounts.
1. Check for any suspicious Dropbox sign-in notifications and review recent account activity. 2. Change your Dropbox account password immediately if you received a suspicious sign-in alert. 3. Enable two-factor authentication (2FA) on your Dropbox account. 4. Be aware that Dropbox has already expired all sessions authenticated through Lenovo IDs. 5. Dropbox has added a new login requirement mandating that users enter their Dropbox account password when attempting to use Lenovo ID authentication — ensure you complete this step if prompted. 6. Organizations using federated identity or SSO integrations with third-party providers should verify that the identity provider properly validates email ownership before allowing account linking. 7. Review and audit any legacy SSO/IdP integrations for similar trust assumption flaws. 8. Ensure that identity-linking flows require confirmation through existing authentication methods before accepting third-party identity assertions.