Dropbox is warning some users that unauthorized attackers accessed their accounts by exploiting a flaw in Lenovo’s email verification process to create fraudulent Lenovo IDs.
Some of the affected users did not have Lenovo accounts. However, Dropbox uses Lenovo Identity Provider Services as part of its authentication infrastructure, allowing users to sign in to Dropbox with a verified Lenovo ID.
According to a notification sent to affected users, “an issue with Lenovo’s email verification process” allowed an unauthorized third party to register a Lenovo ID using the victim’s email address.
The attacker could then use the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without entering the user’s Dropbox password.
Dropbox’s account-linking process appears to have trusted the Lenovo ID authentication, enabling attackers to access accounts without first compromising the users’ email accounts or using their existing Dropbox login credentials.
Dropbox explained:
“While you may not have an existing Lenovo ID, our investigation revealed that an issue with Lenovo’s email verification process could allow an unauthorized third party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with your email address.”

Source: @yonilevy
Several Dropbox users said they received suspicious sign-in notifications about two weeks earlier. Some immediately changed their passwords and enabled two-factor authentication (2FA) to protect their accounts.
“One strange thing happened at the time: The Dropbox login page started offering ‘Continue with SSO’ for my email, even though I had never created a Lenovo ID,” a user identified as Zaphod said.
Dropbox said its investigation found that attackers accessed affected accounts between August 4 and August 21.
Lenovo told BleepingComputer that the security issue involved a legacy integration between Lenovo ID and Dropbox. The flaw could be abused to “unauthorizedly authenticate a particular Dropbox account.”
“Once we identified the issue, Dropbox and Lenovo worked together to quickly mitigate the risk,” a Lenovo spokesperson told BleepingComputer.
The investigation remains ongoing, but Lenovo said its customers are not affected by the incident.
To protect users, Dropbox expired all sessions authenticated through Lenovo ID and introduced additional login requirements. Users must now enter their Dropbox account password when attempting to sign in through Lenovo ID authentication.
According to Reuters, approximately 5,000 Dropbox accounts were accessed. The attackers reportedly viewed and downloaded content from some users’ accounts. BleepingComputer contacted Dropbox for additional information but had not received a response at the time of publication.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



