“an issue with Lenovo's email verification process...allowed an unauthorized party to register a Lenovo ID using your email address,” Dropbox warned
Dropbox has notified some users that an attacker exploited a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs and sign into the victims’ Dropbox accounts without their passwords. The cloud-storage company said the problem stemmed from a legacy link between Lenovo ID and Dropbox that allowed an unauthorized party to authenticate as if they controlled the victim’s email address.
How the flaw worked: Lenovo email verification and a legacy integration
According to the notification sent to impacted users, the attacker “register[ed] a Lenovo ID using your email address.” Dropbox said its identity-linking process trusted Lenovo’s assertion that the attacker controlled that email address and did not require confirmation through the existing Dropbox login method. Lenovo told BleepingComputer the issue was related to a legacy integration between Lenovo ID and Dropbox that could be leveraged “to improperly authenticate certain Dropbox accounts.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTimeline: August 4–21 and early user signs
Dropbox determined the attacker accessed accounts between August 4 and August 21. Some users reported receiving notifications of suspicious Dropbox sign-ins “about two weeks ago,” after which they immediately changed their passwords and enabled two-factor authentication (2FA). One user, xaphod, said they noticed the Dropbox login page had begun offering “Continue with SSO” for their email even though they had never created a Lenovo ID.
Response: actions taken by Dropbox and Lenovo
Dropbox and Lenovo “worked collaboratively to promptly mitigate the risk,” Lenovo told BleepingComputer. Dropbox expired all sessions that had been authenticated through Lenovo IDs and added a new login requirement that mandates users enter their Dropbox account password when attempting to use Lenovo ID authentication. The company’s notification reiterated: “While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
Scope and impact: roughly 5,000 accounts accessed; some data viewed and downloaded
According to Reuters, approximately 5,000 accounts were accessed in the incident, and the attacker viewed and downloaded content from some users. BleepingComputer has contacted Dropbox for additional information but had not received a response as of publication. Dropbox’s changes — expiring Lenovo-authenticated sessions and requiring Dropbox passwords for Lenovo ID logins — are the concrete mitigations the company implemented while the investigation continues. Lenovo also stated the company determined that its own customers were not affected by the issue.
What this means for technologists and security teams, affected enterprises and procurement leaders, and end users
- Technologists and security teams: Watch integrations with third-party identity providers, especially legacy connections. Dropbox’s experience shows that an IdP assertion can bypass local login controls if the relying service does not revalidate ownership through its own authentication flow.
- Affected enterprises and procurement leaders: Review contracts and technical details for identity-provider integrations in vendor services the organization uses; legacy integrations may require explicit reassessment and mitigation to prevent implicit trust from being exploited.
- End users and the general public: If you received a suspicious sign-in notification, change your password and enable two-factor authentication. Users who saw unexpected single-sign-on (SSO) prompts for services they never enrolled with should report them and consider treating those prompts as possible indicators of identity-provider abuses.
The immediate technical fixes — session expiration and requiring Dropbox passwords for Lenovo-based sign-ins — have been applied, and Lenovo described the mitigation as collaborative. The investigation into the breach continues; Reuters’ estimate that roughly 5,000 accounts were accessed and the confirmation that some content was viewed and downloaded make clear that the incident was nontrivial. One remaining, practical question the public will want answered as the probe proceeds is how many users had files exfiltrated and which types of content were affected.
Source: BleepingComputer — Dropbox accounts breached through Lenovo email verification flaw




