Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Dropbox warned about 5,000 users that attackers abused a legacy Lenovo ID login integration to access accounts and files between August 4 and 21.
Attackers exploited an integration allowing Dropbox access via Lenovo IDs, registering Lenovo IDs with Dropbox users' email addresses due to a flaw in Lenovo's email verification process. The compromise lasted from August 4 to 21; attackers accessed files belonging to fewer than a third of the roughly 5,000 affected users, none of whom had 2FA enabled. Bitcoin security company Casa co-founder Jameson Lopp reported attackers attempted to access one locally encrypted file. Dropbox expired all Lenovo ID sessions, severed the integration link, and urged affected users to reset passwords and enable 2FA while Lenovo's investigation continues.
- ~5,000 Dropbox accounts compromised via legacy Lenovo ID integration
- Flaw in Lenovo's email verification let attackers register IDs with victims' addresses
- Files accessed for fewer than a third of affected accounts; none had 2FA
- Dropbox expired Lenovo sessions, severed the link and urged credential resets
Full article263 words · extracted from theregister.com · click to collapse
Security
Cloud storage biz severs old integration and urges victims to reset credentials
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration.
In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs.
Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts.
REG AD
It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password .
REG AD
The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users.
Jameson Lopp , co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd.
Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled.
After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo.
In its email, the company advised affected users to change their Dropbox and personal email passwords and enable 2FA.
Lenovo told Reuters that its customers were unaffected and that its investigation was continuing.
The Register asked Dropbox and Lenovo for more information. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924