Overview
- Dropbox has informed users about unauthorized access to their accounts occurring between August 4 and August 21, attributed to a vulnerability in Lenovo ID authentication.
- One user reported a suspicious login from Canary Wharf in London, using Chrome on a Windows device.
- The company stated that there is no evidence of file viewing or downloading and has since revised the access protocols for Lenovo IDs.
Numerous Dropbox users have been alerted that their accounts were compromised due to a security flaw related to Lenovo ID authentication.
This incident appears to have taken advantage of a vulnerability in Dropbox's single sign-on (SSO) system associated with Lenovo IDs. According to Dropbox, a problem with Lenovo's email verification allowed unauthorized individuals to register Lenovo IDs using other people's email addresses, subsequently gaining access to the Dropbox accounts linked to those addresses.
In a communication to the affected users, Dropbox confirmed that unauthorized access took place between August 4 and August 21, 2026. However, the company noted that its logs did not indicate any files were accessed or downloaded during this time.
“We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled,” a Dropbox representative told Decrypt. “Our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using another person’s email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
“Approximately 5,000 Dropbox accounts were impacted, and fewer than one-third of those accounts had files viewed or downloaded,” the representative added. “We’ve emailed all impacted users directly. Customers with inquiries about their account activity should reach out to our support team. If a user did not receive an email from us, their account was not affected.”
Yoni Levy, a developer among those impacted, shared screenshots of the notification on X.
so dropbox got hacked (never had a Lenovo account, haven't been to UK) pic.twitter.com/UoYRaJFuEC
— yoni | parser.eth (@yonilevy) August 31, 2026
One screenshot revealed a warning from Dropbox indicating that Levy's account was accessed by a new web browser from “Near Canary Wharf, England, United Kingdom” on August 18 at 6:06 a.m. local time, utilizing Chrome on Windows.
Levy stated he neither possesses a Lenovo account nor has he visited the United Kingdom.
A follow-up notification from Dropbox confirmed that an unauthorized party had registered a Lenovo ID using his email address and subsequently accessed his Dropbox account with that ID.
This breach did not seem to require the victim's Dropbox password or access to their email inbox. Dropbox explained that affected accounts were linked to Lenovo IDs that lacked two-factor authentication, which enabled attackers to use newly created Lenovo IDs with matching email addresses to log into existing accounts without further verification.
This incident follows a series of security alerts affecting major online platforms. Recently, users on X reported an influx of unsolicited password-reset emails, strange login alerts, and account lockouts, though X stated it found no evidence of a new breach. An engineer from X indicated that attackers appeared to be attempting to seize control of accounts to access X Money.
