Cyber security NewsNewsSoftware & Apps News

Dropbox’s Lenovo Login Shortcut Just Let Hackers Walk Into 5,000 Accounts

Roughly 5,000 accounts were compromised last month after attackers exploited a verification gap in Lenovo ID, the third-party sign-in option Dropbox offers, letting hackers access accounts without ever needing a victim's password.

Key Takeaways

  • Dropbox said about 5,000 accounts were compromised between August 4 and August 21, with files viewed or downloaded in fewer than a third of them
  • The breach exploited a flaw in Lenovo’s email verification process, allowing attackers to register a Lenovo ID under a victim’s email without proving they controlled that inbox
  • Only accounts without Dropbox’s two-factor authentication enabled were vulnerable to the attack
  • Dropbox has severed all links between Lenovo IDs and Dropbox accounts, and Dropbox shares fell as much as 6.6% in extended trading Tuesday

Dropbox confirmed Tuesday that hackers gained unauthorized access to roughly 5,000 user accounts over a nearly three-week window in August, viewing or downloading stored files in fewer than a third of those cases.

The SaaS-based company began notifying affected users by email on Monday, a day before Bloomberg News first reported the breach publicly.

The issue traced back to Lenovo ID, a single sign-on option that lets Dropbox users log in through a Lenovo-verified identity instead of typing their Dropbox password directly, similar to how other platforms use third-party sign-in systems. 

How Attackers Got In Without a Single Password

The breach was caused by a failure to follow basic cybersecurity practices, not by cracking encryption or guessing passwords. 

Dropbox told Reuters it identified unauthorized access specifically tied to accounts linked through Lenovo ID that hadn’t enabled Dropbox’s two-factor authentication

Combined with a flaw in Lenovo’s own email verification process, an attacker could register a new Lenovo ID under someone else’s email address without ever proving they controlled that inbox. 

Once that unverified identity existed, Dropbox’s system matched it to an existing account and signed the attacker straight in, no password required. 

Reporting from 9to5Mac, citing security researcher findings, noted that in at least one recovered case the rogue account’s display name was simply set to “John Madden,” a detail that suggests bulk, low-effort registration rather than a targeted, sophisticated attack.

Dropbox’s Fix Closes Its Half of the Problem

Dropbox responded quickly by terminating all active Lenovo ID sessions and severing existing Lenovo ID and Dropbox account links. 

It also changed its systems so that, going forward, users must enter their actual Dropbox password before a Lenovo ID can authenticate them at all. 

Dropbox said it also reported the incident to data protection regulators.

Lenovo, for its part, described the issue as a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts,” Reuters noted.

The company maintained that its own core customer services, such as users accessing official portals to register hardware or warranty checks, were not affected, and said its investigation remains ongoing. 

That leaves open an important question: whether Lenovo’s underlying registration flaw has itself been independently verified as fixed.

What makes this breach instructive isn’t the exploit itself, but where the accountability lies. 

Dropbox is right that the root flaw was on Lenovo’s side, where email ownership was poorly verified during registration. 

But 9to5Mac’s reporting highlights Dropbox’s role: it trusted the unverified identity without asking users to confirm their identity when a new Lenovo ID was linked to their account. 

The breach therefore depended on weaknesses at both companies. 

Just as two-factor authentication proved critical during the 17.5 million account Instagram leak, 2FA would have blocked this Dropbox exploit entirely, even with Lenovo’s verification flaw intact.

As “sign in with X” services grow, companies that rely on third-party identity verification also inherit their partners’ security weaknesses.

Users concerned about the incident can also use reputable digital footprint checkers to see whether their email address or other personal information has appeared in known data breaches. 

Source: Dropbox User Accounts Breached by Hackers Who Accessed Data

Fawad Malik

Fawad Malik is a digital marketing professional and technology writer with over 15 years of industry experience. He specializes in SEO, SaaS, AI, consumer technology, internet services, and content strategy. He is the Founder and CEO of WebTech Solutions, a digital agency focused on helping businesses grow through modern online strategies. Through NogenTech, Fawad shares practical insights on internet technology, WiFi, apps, AI tools, digital trends, and the latest tech updates for readers worldwide.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button