
Dropbox users are reporting unauthorized account access caused by a flaw in Lenovo’s email verification process that allowed attackers to create Lenovo IDs using victims’ email addresses and use them to sign in to associated Dropbox accounts.
The number of affected users remains unknown, and neither Dropbox nor Lenovo has published a public advisory about the incident.
The issue surfaced publicly after users said they received a Dropbox security notification warning that their account had been accessed without authorization between August 4 and August 21, 2026. Some said Dropbox had alerted them to an unfamiliar login roughly two weeks earlier.
According to the notification, Dropbox allows Lenovo to act as an identity provider, enabling customers to authenticate to Dropbox using verified Lenovo IDs. Dropbox said its investigation found that a problem in Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID with another person’s email address.
Dropbox is a widely used cloud storage and file-sharing provider serving consumers and businesses, while Lenovo is one of the world’s largest PC manufacturers. The integration between the two companies effectively meant Dropbox trusted Lenovo’s assertion that an email address associated with a Lenovo ID had been verified.
This created an account takeover path in which an attacker could register a Lenovo ID using a victim’s email address, have Lenovo incorrectly treat that address as verified, and then authenticate to the Dropbox account tied to the same email address without knowing its Dropbox password.
Notably, Dropbox says it found no evidence that the user’s files were viewed or downloaded.
Dropbox told affected users it expired all sessions authenticated through Lenovo IDs and severed the Lenovo connection from their accounts. It also changed the login flow so that a Lenovo ID cannot be used to access the affected Dropbox account without first entering the Dropbox password.
One user said Dropbox had unexpectedly begun showing a “Continue with SSO” option for their email address even though they had never created a Lenovo ID, suggesting the authentication linkage may have been established without explicit action by the Dropbox account holder.
It remains unclear how long the vulnerable authentication flow existed, how widely Lenovo ID login was available, or how many Dropbox accounts were accessed.
Affected users should change both their Dropbox and email passwords, enable two-step verification, review active sessions and connected applications, and check Dropbox activity logs for unfamiliar logins or file access.







Leave a Reply