Around 5,000 Dropbox users were warned that attackers gained access to their cloud storage by abusing a legacy Lenovo login integration, the company told affected customers and confirmed to reporters.
Legacy Lenovo ID integration and the email verification flaw
Dropbox said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. In its notification to customers, Dropbox blamed "an issue with Lenovo's email verification process," saying that flaw let attackers register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. Dropbox did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password.
Scope and timeline: August 4–21 and roughly 5,000 accounts
The company told customers the compromise lasted from August 4 to 21. Dropbox warned "around 5,000" users that their accounts had been accessed; it also told Bloomberg attackers accessed files belonging to fewer than a third of the affected users. Dropbox confirmed the scale of the incident to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildEvidence from affected users: Jameson Lopp and a single attempted file view
Among those notified, Jameson Lopp, co‑founder of Bitcoin security company Casa, reported that attackers attempted to access a single file named "IMPORTANT.rtf." Lopp said the file had been encrypted locally before it was uploaded to Dropbox and added, "Sometimes, it pays to be a nerd." His experience underscores that, while many accounts were touched, the attackers' activity did not necessarily result in broad file exfiltration for every impacted user.
Dropbox's remediation steps and customer guidance
After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo. In its email to impacted customers, Dropbox advised them to change both their Dropbox and personal email passwords and to enable 2FA.
Lenovo's response and reporting follow‑up
Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register contacted both Dropbox and Lenovo for additional information.
What this means for end users, security teams, and Lenovo
- End users: Dropbox explicitly instructed affected customers to change Dropbox and personal email passwords and to enable 2FA — steps the company recommended in its notice to those impacted.
- Security teams: The incident centers on a legacy single‑sign‑on path that relied on a third party's email verification. Teams responsible for integrated authentication should take note that a verification weakness in a partner service can be sufficient for account takeover when 2FA is not present.
- Lenovo: The company has said its customers were unaffected while its investigation continues; the record shows Dropbox severed the authentication link and expired Lenovo‑ID sessions after the breach was discovered.
The facts laid out by Dropbox and the reporting partners point to a narrow but consequential vector: a legacy login integration, an email verification gap, and accounts without 2FA. Dropbox acted to revoke the Lenovo‑ID sessions and to cut the link; Lenovo says it is investigating. One clear, concrete question remains in the public record: why did the integration permit access without requiring a Dropbox password — a detail Dropbox noted but did not explain in its customer notice.
Source: The Register — Legacy Lenovo login opens 5,000 Dropbox accounts to attackers




