Dropbox’s Lenovo Login Shortcut Just Let Hackers Walk Into 5,000 Accounts
Roughly 5,000 accounts were compromised last month after attackers exploited a verification gap in Lenovo ID, the third-party sign-in option Dropbox offers, letting hackers access accounts without ever needing a victim's password.

Dropbox confirmed Tuesday that hackers gained unauthorized access to roughly 5,000 user accounts over a nearly three-week window in August, viewing or downloading stored files in fewer than a third of those cases.
The SaaS-based company began notifying affected users by email on Monday, a day before Bloomberg News first reported the breach publicly.
The issue traced back to Lenovo ID, a single sign-on option that lets Dropbox users log in through a Lenovo-verified identity instead of typing their Dropbox password directly, similar to how other platforms use third-party sign-in systems.
How Attackers Got In Without a Single Password
The breach was caused by a failure to follow basic cybersecurity practices, not by cracking encryption or guessing passwords.
Dropbox told Reuters it identified unauthorized access specifically tied to accounts linked through Lenovo ID that hadn’t enabled Dropbox’s two-factor authentication.
Combined with a flaw in Lenovo’s own email verification process, an attacker could register a new Lenovo ID under someone else’s email address without ever proving they controlled that inbox.
Once that unverified identity existed, Dropbox’s system matched it to an existing account and signed the attacker straight in, no password required.
Reporting from 9to5Mac, citing security researcher findings, noted that in at least one recovered case the rogue account’s display name was simply set to “John Madden,” a detail that suggests bulk, low-effort registration rather than a targeted, sophisticated attack.
Dropbox’s Fix Closes Its Half of the Problem
Dropbox responded quickly by terminating all active Lenovo ID sessions and severing existing Lenovo ID and Dropbox account links.
It also changed its systems so that, going forward, users must enter their actual Dropbox password before a Lenovo ID can authenticate them at all.
Dropbox said it also reported the incident to data protection regulators.
Lenovo, for its part, described the issue as a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts,” Reuters noted.
The company maintained that its own core customer services, such as users accessing official portals to register hardware or warranty checks, were not affected, and said its investigation remains ongoing.
That leaves open an important question: whether Lenovo’s underlying registration flaw has itself been independently verified as fixed.
A Reminder That Trust Between Companies Has a Weak Link
What makes this breach instructive isn’t the exploit itself, but where the accountability lies.
Dropbox is right that the root flaw was on Lenovo’s side, where email ownership was poorly verified during registration.
But 9to5Mac’s reporting highlights Dropbox’s role: it trusted the unverified identity without asking users to confirm their identity when a new Lenovo ID was linked to their account.
The breach therefore depended on weaknesses at both companies.
Just as two-factor authentication proved critical during the 17.5 million account Instagram leak, 2FA would have blocked this Dropbox exploit entirely, even with Lenovo’s verification flaw intact.
As “sign in with X” services grow, companies that rely on third-party identity verification also inherit their partners’ security weaknesses.
Users concerned about the incident can also use reputable digital footprint checkers to see whether their email address or other personal information has appeared in known data breaches.
Source: Dropbox User Accounts Breached by Hackers Who Accessed Data



